Description
The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-1487 Vulnerability (CVE-2013-1487)
WordPress 5.2.x PHP Object Injection (5.2 - 5.2.10)
OpenSSL 7PK - Security Features Vulnerability (CVE-2015-1793)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.5.4)
Django Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4140)