Moodle does not check for the moodle/course:viewhiddencourses capability
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 24, 2024
Description
Published by the National Vulnerability Database
May 27, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 24, 2024
Last updated
Jan 24, 2024
enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.
References