Boletines de Vulnerabilidades

MSA-22-0003: Capability gradereport/user:view not always respected when navigating to a users course grade report


Información sobre el sistema

   
Software afectado PHP

Descripción

di Michael Hawkins. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.Severity/Risk:MinorVersions affected:3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versionsVersions fixed:3.11.5, 3.10.9 and 3.9.12Reported by:Deds CastilloCVE identifier:CVE-2022-0334Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=431102&parent=1734816

Identificadores estándar

Propiedad Valor
CVE CVE-2022-0334.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2022-05-17
Ministerio de Defensa
CNI
CCN
CCN-CERT