Vulnerability Bulletins

MSA-23-0051: Badge recipients are available to all users


System information

   
Affected software PHP

Description

by Michael Hawkins. Insufficient capability checks meant it was possible for all users to view the recipients of badges.Severity/Risk:MinorVersions affected:4.3, 4.2 to 4.2.3, 4.1 to 4.1.6, 4.0 to 4.0.11, 3.11 to 3.11.17, 3.9 to 3.9.24 and earlier unsupported versionsVersions fixed:4.3.1, 4.2.4, 4.1.7, 4.0.12, 3.11.18 and 3.9.25Reported by:Sara Arjona (@sarjona)CVE identifier:CVE-2023-6668Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=453765&parent=1823293

Standar resources

Property Value
CVE CVE-2023-6668.

Version history

Version Comments Date
Ministerio de Defensa
CNI
CCN
CCN-CERT