On certain Moodle sites, it was possible to retrieve user data, including names, contact information, and hashed passwords, via a stack trace returned by an API call. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability. Versions affected: 4.5 to 4.5.2 Versions fixed: 4.5.3