Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c5g-w3gf-rf4f

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle allows attackers to obtain username and course information

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 2.4.11

2.4.11

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.7

2.5.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.4

2.6.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.1

2.7.1

EPSS

Процентиль: 51%
0.00283
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

nvd
около 11 лет назад

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

debian
около 11 лет назад

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x ...

EPSS

Процентиль: 51%
0.00283
Низкий