Описание
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
esm-apps/bionic | needs-triage | |
esm-apps/xenial | needs-triage | |
trusty | ignored | end of standard support |
upstream | needs-triage | |
xenial | ignored | end of standard support |
Показывать по
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...
Moodle Insecure direct object reference (IDOR) in a calendar web service
Уязвимость системы управления Moodle, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить привилегии
5 Medium
CVSS2
5.3 Medium
CVSS3