Sceawere
Vulnerability Detail
CVE-2026-102587UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Moodle User Filter Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 3h ago
- Vendor
- —
- Product
- N/A
- Attack Type
- Observable Response Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-09-30T09:17:16.023Z",
"pubdate": "2026-09-30T09:17:16.023Z",
"executiveSummary": "A security vulnerability exists in Moodle related to the improper enforcement of visibility restrictions within user list filters.\nThe vulnerability is classified as an information disclosure flaw where sensitive user profile data can be inferred by unauthorized personnel.\nThe issue specifically impacts authorized users with 'manager' privileges, who are restricted from viewing certain user profile fields but can bypass these constraints via the filtering interface.\nBy manipulating search parameters in the user listing functionality, a malicious actor can confirm the existence or specific values of hidden attributes for target users.\nThis represents a significant breach of privacy and data security policies, as metadata or sensitive profile information is leaked through inference-based attacks.\nExploitation requires the attacker to possess manager-level credentials within the Moodle environment, allowing them to leverage legitimate system functions to exfiltrate data they are not permissioned to access.\nThe risk is primarily centered on unauthorized access to PII (Personally Identifiable Information) that administrators intended to keep private from certain staff roles.",
"technicalDetails": "The root cause of this vulnerability lies in the lack of attribute-level access control verification during the construction of SQL queries or data retrieval processes within the Moodle user listing/filtering engine.\nWhile the Moodle framework provides mechanisms to restrict visibility of user profile fields, the filtering component fails to apply these same security policies when processing query criteria.\nWhen a manager user interacts with the user filtering interface, the application constructs queries based on provided attributes. If a manager specifies a hidden profile field as a filter criterion, the backend performs the filtering operation regardless of whether the specific user record or the field itself is subject to visibility restrictions for the user's role.\nAn attacker can exploit this via an inference-based attack vector. For example, if a manager wishes to determine the hidden 'department' or 'custom profile field' value of a specific user, they can construct a list filter that includes that specific field with a known value.\nBy observing whether the application returns the target user in the filtered result set or provides feedback on the result count, the attacker can systematically deduce the contents of protected fields. If the user appears in the results when the filter matches a specific hidden value, the attacker confirms the attribute value.\nThe vulnerable component is the user filtering subsystem that interacts with the user profile database schema. This bypass occurs because the logical checks for 'can_view_user_field' are either bypassed or insufficiently integrated into the filter's query builder class.\nAuthentication is required to trigger this vulnerability, as the attacker must be authenticated as a manager. However, no additional complex payloads are needed beyond standard web requests that utilize the Moodle filtering API.\nThe post-exploitation impact includes the unauthorized disclosure of PII or institutional metadata that is protected by granular privacy settings. This effectively allows an attacker to map hidden organizational relationships, user demographics, or private contact details, potentially violating privacy compliance frameworks such as GDPR or FERPA."
}