Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p586-c547-p893

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

EPSS

Процентиль: 41%
0.00189
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 13 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

nvd
почти 13 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.

debian
почти 13 лет назад

The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x ...

EPSS

Процентиль: 41%
0.00189
Низкий

Дефекты

CWE-287