Lucene search

K
osvGoogleOSV:CVE-2021-20283
HistoryMar 15, 2021 - 10:15 p.m.

CVE-2021-20283

2021-03-1522:15:13
Google
osv.dev
7
web service
user permissions
enrolled courses
moodle
software issue

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

40.5%

The web service responsible for fetching other users’ enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

40.5%