The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 05:46
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1939051 - Issue Tracking, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFSNJ7XHVTC52RSRX2GBQFF3VEEAY2MS/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UFH5DDMU5TZ3JT4Q52WMRAHACA5MHIMT/ - | |
References | () https://moodle.org/mod/forum/discuss.php?d=419654 - Patch, Vendor Advisory |
07 Nov 2023, 03:29
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-03-15 22:15
Updated : 2024-11-21 05:46
NVD link : CVE-2021-20283
Mitre link : CVE-2021-20283
CVE.ORG link : CVE-2021-20283
JSON object : View
Products Affected
moodle
- moodle
fedoraproject
- fedora