Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p54-pc88-36c4

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle does not properly restrict access to category and course data

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.1, < 2.1.2

2.1.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.5

2.0.5

EPSS

Процентиль: 49%
0.0026
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
почти 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

nvd
почти 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

debian
почти 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

EPSS

Процентиль: 49%
0.0026
Низкий

Дефекты

CWE-284