Описание
Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
Пакеты
moodle/moodle
< 4.1.12
4.1.12
moodle/moodle
>= 4.2.0-beta, < 4.2.9
4.2.9
moodle/moodle
>= 4.3.0-beta, < 4.3.6
4.3.6
moodle/moodle
>= 4.4.0-beta, < 4.4.2
4.4.2
EPSS
6.6 Medium
CVSS4
7.5 High
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
A flaw was found in Feedback. Bulk messaging in the activity's non-res ...
EPSS
6.6 Medium
CVSS4
7.5 High
CVSS3