Lucene search

K
osvGoogleOSV:GHSA-2M72-M5CW-3G9H
HistoryMay 24, 2022 - 5:44 p.m.

Missing permission check in Moodle

2022-05-2417:44:37
Google
osv.dev
4
moodle
web service
permission validation
enrolled courses
software vulnerability

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

40.5%

The web service responsible for fetching other users’ enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

40.5%