Lucene search

K
osvGoogleOSV:GHSA-5RR5-FXHC-JV64
HistoryMay 13, 2022 - 1:12 a.m.

Moodle allows attackers to modify the visibility of a badge

2022-05-1301:12:51
Google
osv.dev
15
moodle
badge visibility
security flaw
remote users

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

47.2%

badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

47.2%