Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93pj-4p65-qmr9

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Insufficient user authorization in Moodle

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11, < 3.11.5

3.11.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.10, < 3.10.8

3.10.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 3.9.11

3.9.11

EPSS

Процентиль: 45%
0.00226
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

CVSS3: 4.3
nvd
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

CVSS3: 4.3
debian
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

EPSS

Процентиль: 45%
0.00226
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-863