Lucene search

K
redosRedosROS-20220329-02
HistoryMar 29, 2022 - 12:00 a.m.

ROS-20220329-02

2022-03-2900:00:00
redos.red-soft.ru
45
moodle
course management
user data
badges criteria
sql commands
database
permissions
privileges
access control
deletion
improper access control
course icons
profile fields

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

37.0%

Vulnerability in the Moodle course management system, related to insufficient cleansing of user data in the
Badges criteria code. Exploitation of the vulnerability could allow an attacker acting remotely,
send a specially crafted query to the affected application and execute arbitrary SQL commands on the application’s database
application database

Vulnerability in the Moodle course management system, related to permissions, privileges and access control.
access. Exploitation of the vulnerability could allow an attacker, acting remotely, to delete
users

Vulnerability in the Moodle course management system, related to improper access control. Exploitation
of the vulnerability could allow an attacker acting remotely to customize course icons using criteria for
profile fields

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64moodle< 3.11.4-2UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

37.0%