Описание
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | code not present |
| cosmic | ignored | end of life |
| devel | not-affected | code not present |
| disco | not-affected | code not present |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/xenial | not-affected | code not present |
| esm-infra-legacy/trusty | DNE | |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 67%
0.01318
Низкий
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
nvd
около 7 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
CVSS3: 7.5
debian
около 7 лет назад
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service f ...
CVSS3: 7.5
github
около 4 лет назад
Moodle all messaging conversations could be viewed
EPSS
Процентиль: 67%
0.01318
Низкий
5 Medium
CVSS2
7.5 High
CVSS3