Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhc7-xhc2-7p7w

Опубликовано: 25 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Moodle self enrollment available before completing second factor with MFA enabled

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.3.0-beta, < 4.3.12

4.3.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.4.0-beta, < 4.4.8

4.4.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.4

4.5.4

EPSS

Процентиль: 55%
0.00317
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.3
ubuntu
11 месяцев назад

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
nvd
11 месяцев назад

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

CVSS3: 4.3
debian
11 месяцев назад

A security vulnerability was discovered in Moodle that allows students ...

CVSS3: 4.3
fstec
12 месяцев назад

Уязвимость компонента Multi-Factor Authentication виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или выполнить произвольный код

CVSS3: 5.3
redos
10 месяцев назад

Множественные уязвимости moodle

EPSS

Процентиль: 55%
0.00317
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287