Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp8m-h777-g4p3

Опубликовано: 19 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Access Control in moodle

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.3.0, < 4.3.3

4.3.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.6

4.2.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.1.9

4.1.9

EPSS

Процентиль: 26%
0.00088
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
nvd
больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
debian
больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts ...

EPSS

Процентиль: 26%
0.00088
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284