Описание
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | not-affected | 2.7.13+dfsg-1 |
cosmic | not-affected | 2.7.13+dfsg-1 |
devel | not-affected | 2.7.13+dfsg-1 |
disco | not-affected | 2.7.13+dfsg-1 |
esm-apps/bionic | not-affected | 2.7.13+dfsg-1 |
esm-apps/xenial | not-affected | 2.7.13+dfsg-1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x ...
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю получить доступ к защищаемой информации
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3