Junglewise Threat Intelligence

CVE-2016-5014: Moodle information disclosure in Event Monitor notifications

CVE-2016-5014 · Severity: medium · CVSS 5.4 · Published 2017-01-20

Technologies: Moodle. Vendors: Moodle.

Executive brief

A flaw in the Moodle learning management system allows users who have been unenrolled from a course to continue receiving automated notifications from that course. This could lead to the unauthorized disclosure of course updates or sensitive information to individuals who should no longer have access. Organizations using Moodle for private or sensitive training should ensure they have applied the relevant security patches.

Technical details

An information disclosure vulnerability exists in Moodle versions 2.x and 3.x within the Event Monitor component. The root cause is a failure to properly terminate notification subscriptions when a user is unenrolled from a course. As a result, a remote user who was previously enrolled can continue to receive event notifications via the network despite losing authorized access to the course content. This is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Patches have been released by the vendor to address this behavior.

Affected products

  • Moodle Moodle 2.x, 3.0.x, 3.1.0

Timeline

  • 2016-07-18: advisory: Vendor advisory published by Moodle
  • 2017-01-20: disclosed: NVD publication date

References

Related threats