Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxqh-mx28-7ghw

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Moodle Portfolio script allows instantiation of class chosen by user

An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.1, < 3.1.12

3.1.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.2, < 3.2.9

3.2.9

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.3, < 3.3.6

3.3.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.4, < 3.4.3

3.4.3

EPSS

Процентиль: 65%
0.00499
Низкий

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

CVSS3: 8.1
nvd
около 7 лет назад

An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

CVSS3: 8.1
debian
около 7 лет назад

An issue was discovered in Moodle 3.x. By substituting URLs in portfol ...

EPSS

Процентиль: 65%
0.00499
Низкий

8.1 High

CVSS3

Дефекты

CWE-20