Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-3640

Опубликовано: 25 апр. 2025
Источник: debian

Описание

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodleremovedpackage

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 2 месяцев назад

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

CVSS3: 4.3
nvd
около 2 месяцев назад

A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

CVSS3: 4.3
github
около 2 месяцев назад

Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users

CVSS3: 4.3
fstec
около 2 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с обходом авторизации посредством ключа, контролируемого пользователем, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 8.8
redos
около 1 месяца назад

Множественные уязвимости moodle