Описание
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
Ссылки
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
- Issue TrackingThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.8.9 (включая)Версия от 3.9.0 (включая) до 3.9.12 (исключая)Версия от 3.10.0 (включая) до 3.10.9 (исключая)Версия от 3.11.0 (включая) до 3.11.5 (исключая)
Одно из
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.0025
Низкий
3.8 Low
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 3.8
ubuntu
больше 3 лет назад
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
CVSS3: 3.8
debian
больше 3 лет назад
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...
EPSS
Процентиль: 48%
0.0025
Низкий
3.8 Low
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863
CWE-863