Описание
Moodle IDOR when accessing list of course badges
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Пакеты
moodle/moodle
>= 4.4.0-beta, < 4.4.3
4.4.3
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
A vulnerability was found in Moodle. Additional checks are required to ...
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3