Описание
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2. ...
Moodle mishandles group-based authorization checks
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю получить конфиденциальную информацию
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2