Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m434-m5pv-p35w

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.8

Описание

Insufficient user authorization in Moodle

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11, < 3.11.5

3.11.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.10, < 3.10.8

3.10.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9, < 3.9.11

3.9.11

EPSS

Процентиль: 48%
0.0025
Низкий

3.8 Low

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.8
ubuntu
почти 4 года назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

CVSS3: 3.8
nvd
почти 4 года назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

CVSS3: 3.8
debian
почти 4 года назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

EPSS

Процентиль: 48%
0.0025
Низкий

3.8 Low

CVSS3

Дефекты

CWE-863