Описание
Moodle has an IDOR in badges allows disabling of arbitrary badges
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Пакеты
moodle/moodle
>= 4.5.0-beta, < 4.5.2
4.5.2
moodle/moodle
>= 4.4.0-beta, < 4.4.6
4.4.6
moodle/moodle
>= 4.3.0-beta, < 4.3.10
4.3.10
moodle/moodle
< 4.1.16
4.1.16
Связанные уязвимости
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Insufficient capability checks made it possible to disable badges a us ...
Уязвимость виртуальной обучающей среды Moodle, связанная с недостатками контроля доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации