Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcrj-gmr6-p5j8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle Allows Modification of Constants

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 1.9.14

1.9.14

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.0, < 2.0.5

2.0.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.1, < 2.1.2

2.1.2

EPSS

Процентиль: 51%
0.00274
Низкий

Дефекты

CWE-471

Связанные уязвимости

ubuntu
почти 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

nvd
почти 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

debian
почти 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

EPSS

Процентиль: 51%
0.00274
Низкий

Дефекты

CWE-471