CVE-2006-4937

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/09/2006
Last modified:
01/12/2020

Description

lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 1.6.1 (including)
cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools