Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q53j-c866-h9mw

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 1.3

Описание

Moodle doesn't properly check role

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 1.8.0, < 1.8.12

1.8.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 1.9.0, < 1.9.8

1.9.8

EPSS

Процентиль: 51%
0.00273
Низкий

1.3 Low

CVSS4

Дефекты

CWE-862

Связанные уязвимости

ubuntu
около 15 лет назад

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

redhat
около 15 лет назад

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

nvd
около 15 лет назад

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

debian
около 15 лет назад

user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 doe ...

EPSS

Процентиль: 51%
0.00273
Низкий

1.3 Low

CVSS4

Дефекты

CWE-862