Description
The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2000-0967)
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-41800)
WordPress Plugin Database for Contact Form 7, WPforms, Elementor forms Cross-Site Scripting (1.1.5)
IBM RTC CVE-2019-4084 Vulnerability (CVE-2019-4084)
MediaWiki Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-9487)