Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r38-f9p6-3f7p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS

Процентиль: 38%
0.00162
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

nvd
почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

debian
почти 12 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ...

EPSS

Процентиль: 38%
0.00162
Низкий

Дефекты

CWE-287