Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-3397

Опубликовано: 23 июл. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

РелизСтатусПримечание
devel

not-affected

2.2.3.dfsg-2.1
hardy

ignored

end of life
lucid

not-affected

natty

not-affected

oneiric

not-affected

precise

not-affected

upstream

released

2.2.3.dfsg-2.1

Показывать по

EPSS

Процентиль: 50%
0.00269
Низкий

4 Medium

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

debian
почти 13 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, ...

github
около 3 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

EPSS

Процентиль: 50%
0.00269
Низкий

4 Medium

CVSS2