Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxhx-gmhm-623c

Опубликовано: 29 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Access Control in moodle

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9.0, < 3.9.3

3.9.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.8.0, < 3.8.6

3.8.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.7.0, < 3.7.9

3.7.9

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5, < 3.5.15

3.5.15

EPSS

Процентиль: 71%
0.00701
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
nvd
больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
debian
больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in ...

EPSS

Процентиль: 71%
0.00701
Низкий

7.5 High

CVSS3

Дефекты

CWE-284