Lucene search

K
osvGoogleOSV:GHSA-267J-CWVG-J28C
HistoryMay 13, 2022 - 1:12 a.m.

Moodle attackers to modify grade metadata

2022-05-1301:12:51
Google
osv.dev
11
moodle
grade
metadata
remote users
security vulnerability

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

47.2%

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

47.2%