CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
AI Score
Confidence
Low
EPSS
Percentile
15.5%
moodle/moodle is vulnerable to Authorization Bypass. The vulnerability is due to insufficient permission checks, which allow unauthorized users to add comments to the comments block on another user’s dashboard when it is not otherwise available.