Описание
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | 2.7.11+dfsg-2 |
bionic | not-affected | 2.7.11+dfsg-2 |
cosmic | not-affected | 2.7.11+dfsg-2 |
devel | not-affected | 2.7.11+dfsg-2 |
disco | not-affected | 2.7.11+dfsg-2 |
esm-apps/bionic | not-affected | 2.7.11+dfsg-2 |
esm-apps/xenial | not-affected | 2.7.11+dfsg-2 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
Показывать по
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x ...
Moodle allows attackers to bypass intended access restrictions
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю обойти существующие ограничения доступа
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3