Lucene search

K
osvGoogleOSV:GHSA-2VHR-4MHQ-M35C
HistoryMay 13, 2022 - 1:12 a.m.

Moodle does not properly restrict access

2022-05-1301:12:50
Google
osv.dev
2

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.2%

The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.2%