Описание
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-5551
- https://github.com/moodle/moodle/commit/2bb6c551cf2e7be29857db35388911b8179394b0
- https://github.com/moodle/moodle/commit/6de45d2c9f7dd7b24210ab0310c296366a82986a
- https://github.com/moodle/moodle/commit/b91feb0b2328cdda2561d68b8dfe2a129190bc85
- https://bugzilla.redhat.com/show_bug.cgi?id=2243453
- https://moodle.org/mod/forum/discuss.php?d=451592
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79310
Пакеты
moodle/moodle
>= 4.3.0-beta, < 4.3.0-rc2
4.3.0-rc2
moodle/moodle
>= 4.2.0, < 4.2.3
4.2.3
moodle/moodle
>= 4.1.0, < 4.1.6
4.1.6
moodle/moodle
>= 4.0.0, < 4.0.11
4.0.11
moodle/moodle
>= 3.10.0, < 3.11.17
3.11.17
moodle/moodle
< 3.9.24
3.9.24
Связанные уязвимости
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Separate Groups mode restrictions were not honoured in the forum summa ...
Уязвимость виртуальной обучающей среды Moodle, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации