CVE-2017-15110: Moodle
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
Affected products
- Moodle Moodle: up to and including 3.0.10; from 3.1, up to and including 3.1.8; from 3.2, up to and including 3.2.5; from 3.3, up to and including 3.3.2
Published 2017-11-20. Last modified 2026-06-17.