Lucene search

K
osvGoogleOSV:GHSA-8VJJ-WF73-W882
HistoryMay 13, 2022 - 1:13 a.m.

Moodle Incorrect Default Settings

2022-05-1301:13:17
Google
osv.dev
3
moodle
configuration
vulnerability
teacher role

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

65.2%

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

65.2%

Related for OSV:GHSA-8VJJ-WF73-W882