Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59j6-8g7w-prf7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle exposes hidden grades to students

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.3

2.7.3

EPSS

Процентиль: 48%
0.00252
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

nvd
больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

debian
больше 10 лет назад

lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not ...

EPSS

Процентиль: 48%
0.00252
Низкий

Дефекты

CWE-200