Описание
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 2.5.1-1 |
esm-apps/xenial | not-affected | 2.5.1-1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [2.5.1-1]] |
lucid | ignored | end of life |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | not-affected | 2.5.1-1 |
trusty | not-affected | 2.5.1-1 |
Показывать по
EPSS
4 Medium
CVSS2
Связанные уязвимости
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo ...
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
EPSS
4 Medium
CVSS2