Описание
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
Ссылки
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6.4 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00236
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-285
NVD-CWE-Other
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 6 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVSS3: 7.5
debian
почти 6 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service f ...
CVSS3: 7.5
github
около 3 лет назад
Moodle all messaging conversations could be viewed
EPSS
Процентиль: 47%
0.00236
Низкий
6.5 Medium
CVSS3
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-285
NVD-CWE-Other