Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phqj-xp48-7p7c

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

Moodle does not use the forceloginforprofiles setting for course-profiles access control

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.2

2.0.2

EPSS

Процентиль: 51%
0.00283
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-200
CWE-284

Связанные уязвимости

ubuntu
почти 13 лет назад

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

nvd
почти 13 лет назад

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.

debian
почти 13 лет назад

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setti ...

EPSS

Процентиль: 51%
0.00283
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-200
CWE-284