Executive brief
Moodle, a widely used learning management system, contains a flaw in its glossary search functionality. This issue allows users to view glossary entries they are not authorized to see, potentially exposing private or restricted educational content. This could lead to the unauthorized disclosure of sensitive information within a course or organization.
Technical details
An information disclosure vulnerability (CWE-200) exists in Moodle 3.1.x. The root cause is a failure in the glossary search component to perform adequate authorization checks before displaying search results. A remote, unauthenticated attacker can exploit this by performing a search, which may return and display glossary entries that the user does not have the required permissions to view. This allows for the bypass of intended access controls on glossary content. A patch has been released by the vendor to address this permission check failure.
Affected products
- Moodle Moodle 3.1.0, 3.1.0 beta, 3.1.0 rc1, 3.1.0 rc2
Timeline
- 2016-07-18: disclosed: Initial disclosure via SecurityFocus and Moodle forums
- 2017-01-20: advisory: NVD publication date
- 2016-07-18: patched: Vendor advisory and patch released