Boletines de Vulnerabilidades

MSA-20-0018: Some database module web services did not respect group settings


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. Some database module web services allowed students to add entries within groups they did not belong to.Severity/Risk:MinorVersions affected:3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versionsVersions fixed:3.10, 3.9.3, 3.8.6, 3.7.9 and 3.5.15Reported by:Dani PalouCVE identifier:CVE-2020-25700Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-67015Tracker issue:MDL-67015 Some database

More info:

https://moodle.org/mod/forum/discuss.php?d=413938&parent=1668773

Identificadores estándar

Propiedad Valor
CVE CVE-2020-25700.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2020-11-17
Ministerio de Defensa
CNI
CCN
CCN-CERT