Описание
Moodle's IDOR in badges allows deletion of arbitrary badges
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
Пакеты
moodle/moodle
< 4.1.12
4.1.12
moodle/moodle
>= 4.2.0-beta, < 4.2.9
4.2.9
moodle/moodle
>= 4.3.0-beta, < 4.3.6
4.3.6
moodle/moodle
>= 4.4.0-beta, < 4.4.2
4.4.2
EPSS
6.6 Medium
CVSS4
7.5 High
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
A vulnerability was found in Moodle. Insufficient capability checks ma ...
Уязвимость виртуальной обучающей среды Moodle, связанная с отсутствием авторизации, позволяющая нарушителю удалить данные
EPSS
6.6 Medium
CVSS4
7.5 High
CVSS3