Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20283
HistoryMar 15, 2021 - 9:36 p.m.

CVE-2021-20283

2021-03-1521:36:11
CWE-863
redhat
www.cve.org
5
web service
moodle
unauthorized access
enrolled courses
permission validation
cve-2021-20283

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

40.5%

The web service responsible for fetching other users’ enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

CNA Affected

[
  {
    "product": "moodle",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in 3.10.2, 3.9.5, 3.8.8, 3.5.17"
      }
    ]
  }
]

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

40.5%