Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-0217

enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-0217
  • Moodle » Moodle » Version: 2.6.0
    cpe:2.3:a:moodle:moodle:2.6.0
  • Moodle » Moodle » Version: 2.6.1
    cpe:2.3:a:moodle:moodle:2.6.1
  • Moodle » Moodle » Version: 2.6.2
    cpe:2.3:a:moodle:moodle:2.6.2


Contact Us

Shodan ® - All rights reserved