Lucene search

K
cvelistRedhatCVELIST:CVE-2022-0984
HistoryApr 29, 2022 - 4:05 p.m.

CVE-2022-0984

2022-04-2916:05:10
CWE-863
redhat
www.cve.org
5
users management
badge configuration
bypassing restrictions

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.7%

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CNA Affected

[
  {
    "product": "moodle",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "moodle 3.11.6, moodle 3.10.10, moodle 3.9.13"
      }
    ]
  }
]

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.7%