Описание
Moodle allows users to retrieve information they did not have permission to access
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
Пакеты
moodle/moodle
< 4.1.13
4.1.13
moodle/moodle
>= 4.2.0-beta, < 4.2.10
4.2.10
moodle/moodle
>= 4.3.0-beta, < 4.3.7
4.3.7
moodle/moodle
>= 4.4.0-beta, < 4.4.3
4.4.3
EPSS
5.3 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
A flaw was found in Moodle. Dynamic tables did not enforce capability ...
Уязвимость модуля core_table/dynamic виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
5.3 Medium
CVSS4
6.5 Medium
CVSS3