Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fcv-4qp9-pg32

Опубликовано: 23 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Moodle sends quiz-related messages to inactive/suspended users

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.3

5.0.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.7

4.5.7

EPSS

Процентиль: 9%
0.00033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 2 месяцев назад

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

CVSS3: 4.3
nvd
около 2 месяцев назад

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

CVSS3: 4.3
debian
около 2 месяцев назад

Moodle failed to verify enrolment status correctly when sending quiz n ...

EPSS

Процентиль: 9%
0.00033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863