Boletines de Vulnerabilidades

MSA-23-0047: Logs and Live logs course reports did not respect activity group settings


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. Separate Groups mode restrictions were not honoured in the Logs and Live logs course reports, which would display users from other groups.Severity/Risk:MinorVersions affected:4.3, 4.2 to 4.2.3, 4.1 to 4.1.6, 4.0 to 4.0.11, 3.11 to 3.11.17, 3.9 to 3.9.24 and earlier unsupported versionsVersions fixed:4.3.1, 4.2.4, 4.1.7, 4.0.12, 3.11.18 and 3.9.25Reported by:Ankit AgarwalCVE identifier:CVE-2023-6664Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=453761&parent=1823288

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Data
Ministerio de Defensa
CNI
CCN
CCN-CERT