Описание
moodle: IDOR in edit/delete RSS feed
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
Пакеты
moodle/moodle
< 4.1.14
4.1.14
moodle/moodle
>= 4.2.0, < 4.2.11
4.2.11
moodle/moodle
>= 4.3.0, < 4.3.8
4.3.8
moodle/moodle
>= 4.4.0, < 4.4.4
4.4.4
EPSS
6.9 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
A vulnerability was found in Moodle. Additional checks are required to ...
Уязвимость виртуальной обучающей среды Moodle, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к элементам системы
EPSS
6.9 Medium
CVSS4
6.5 Medium
CVSS3