Описание
Moodle IDOR when deleting OAuth2 linked accounts
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
Пакеты
moodle/moodle
< 4.1.13
4.1.13
moodle/moodle
>= 4.2.0-beta, < 4.2.10
4.2.10
moodle/moodle
>= 4.3.0-beta, < 4.3.7
4.3.7
moodle/moodle
>= 4.4.0-beta, < 4.4.3
4.4.3
EPSS
5.3 Medium
CVSS4
7.5 High
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
A flaw was found in Moodle. Additional checks were required to ensure ...
Уязвимость виртуальной обучающей среды Moodle, связанная с недостатками контроля доступа, позволяющая нарушителю получить несанкционированный доступ к ограниченным функциональным возможностям
EPSS
5.3 Medium
CVSS4
7.5 High
CVSS3