Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62wv-866c-rh86

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

Moodle does not properly restrict comment capabilities

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.4

2.0.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.1

2.1.1

EPSS

Процентиль: 66%
0.00519
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-863

Связанные уязвимости

ubuntu
почти 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

nvd
почти 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

debian
почти 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 do ...

EPSS

Процентиль: 66%
0.00519
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-863