Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29740
HistoryMar 17, 2021 - 4:59 a.m.

Insecure Access Control

2021-03-1704:59:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
moodle
access control
validation
web service
enrolled courses
permission

EPSS

0.001

Percentile

40.5%

moodle/moodle does not properly validate user’s access. The web service responsible for fetching users that are enrolled courses did not validate that the requesting user has the permission to view the information in each course.

EPSS

0.001

Percentile

40.5%