Описание
Moodle all messaging conversations could be viewed
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-10154
- https://github.com/moodle/moodle/commit/2904a7f851da8e66be12f41d55068bf07817fbd6
- https://github.com/moodle/moodle/commit/a3d19efab4aff83c07db9f0ad34c8f0e1f29c64c
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10154
- https://moodle.org/mod/forum/discuss.php?d=386521
Пакеты
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 3.6, < 3.6.4
3.6.4
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 6 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVSS3: 7.5
nvd
почти 6 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVSS3: 7.5
debian
почти 6 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service f ...