CVE-2016-0724 describes an information disclosure vulnerability in Moodle versions prior to 2.6.11, 2.7.12, 2.8.10, 2.9.4, and 3.0.2, affecting the core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info web services. This flaw allows remote authenticated users to access sensitive information about hidden courses without proper authorization. The vulnerability has a CVSS v3 score of 4.3 (Medium), indicating a low attack complexity and no user interaction required, but only a low impact on confidentiality. It is rated as a low risk by FAUCET (12/100). There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.11CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
2.7.0CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:2.7.0:*:*:*:*:*:*:* | ||
2.7.1CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:2.7.1:*:*:*:*:*:*:* | ||
2.7.2CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:2.7.2:*:*:*:*:*:*:* | ||
2.7.3CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:2.7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.