{"api_version":"1","generated_at":"2026-07-23T06:11:03+00:00","cve":"CVE-2017-15110","urls":{"html":"https://cve.report/CVE-2017-15110","api":"https://cve.report/api/cve/CVE-2017-15110.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-15110","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-15110"},"summary":{"title":"CVE-2017-15110","description":"In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.","state":"PUBLISHED","assigner":"redhat","published_at":"2017-11-20 14:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","improper access control"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/101909","name":"http://www.securityfocus.com/bid/101909","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Moodle CVE-2017-15110 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://moodle.org/mod/forum/discuss.php?d=361784","name":"https://moodle.org/mod/forum/discuss.php?d=361784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Mitigation","Vendor Advisory"],"title":"Moodle.org: MSA-17-0021: Students can find out email addresses of other students in the same course","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-15110","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15110","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Moodle 3.x","version":"affected Moodle 3.x","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"15110","vulnerable":"1","versionEndIncluding":"3.0.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"15110","vulnerable":"1","versionEndIncluding":"3.1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"15110","vulnerable":"1","versionEndIncluding":"3.2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"15110","vulnerable":"1","versionEndIncluding":"3.3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"15110","cve":"CVE-2017-15110","epss":"0.002370000","percentile":"0.465700000","score_date":"2026-05-14","updated_at":"2026-05-15 00:08:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:50:16.042Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"101909","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/101909"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://moodle.org/mod/forum/discuss.php?d=361784"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Moodle 3.x","vendor":"n/a","versions":[{"status":"affected","version":"Moodle 3.x"}]}],"datePublic":"2017-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students."}],"problemTypes":[{"descriptions":[{"description":"improper access control","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-22T10:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"101909","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/101909"},{"tags":["x_refsource_CONFIRM"],"url":"https://moodle.org/mod/forum/discuss.php?d=361784"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2017-15110","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Moodle 3.x","version":{"version_data":[{"version_value":"Moodle 3.x"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"improper access control"}]}]},"references":{"reference_data":[{"name":"101909","refsource":"BID","url":"http://www.securityfocus.com/bid/101909"},{"name":"https://moodle.org/mod/forum/discuss.php?d=361784","refsource":"CONFIRM","url":"https://moodle.org/mod/forum/discuss.php?d=361784"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2017-15110","datePublished":"2017-11-20T14:00:00.000Z","dateReserved":"2017-10-08T00:00:00.000Z","dateUpdated":"2024-08-05T19:50:16.042Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-20 14:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","improper access control"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.10","matchCriteriaId":"AEE2C318-E06D-4270-836A-48F07562EE3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1","versionEndIncluding":"3.1.8","matchCriteriaId":"83BC3C5B-EDCF-4838-B271-715E37F4ED3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndIncluding":"3.2.5","matchCriteriaId":"C7325E47-944C-4D40-B679-28CD6EDD64BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3","versionEndIncluding":"3.3.2","matchCriteriaId":"6303BBDF-8425-4BA5-981A-0553CAA88106"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"15110","Ordinal":"1","Title":"CVE-2017-15110","CVE":"CVE-2017-15110","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"15110","Ordinal":"1","NoteData":"In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.","Type":"Description","Title":"CVE-2017-15110"},{"CveYear":"2017","CveId":"15110","Ordinal":"2","NoteData":"2017-11-20","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"15110","Ordinal":"3","NoteData":"2017-11-22","Type":"Other","Title":"Modified"}]}}}