Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5p2x-8427-9fgp

Опубликовано: 12 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Moodle Improper Access Control vulnerability

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

<= 4.2.0

Отсутствует

EPSS

Процентиль: 22%
0.00068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
nvd
больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
debian
больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allo ...

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость виртуальной обучающей среды Moodle, связанная с недостатками контроля доступа, позволяющая нарушителю с ролью student создавать произвольные события

EPSS

Процентиль: 22%
0.00068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284