Описание
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Ссылки
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.5.0 (включая) до 3.5.17 (исключая)Версия от 3.8.0 (включая) до 3.8.8 (исключая)Версия от 3.9.0 (включая) до 3.9.5 (исключая)Версия от 3.10.0 (включая) до 3.10.2 (исключая)
Одно из
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00266
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-863
CWE-862
Связанные уязвимости
CVSS3: 4.3
ubuntu
больше 4 лет назад
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
CVSS3: 4.3
debian
больше 4 лет назад
The web service responsible for fetching other users' enrolled courses ...
EPSS
Процентиль: 50%
0.00266
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-863
CWE-862