Vulnerability Bulletins

MSA-22-0003: Capability gradereport/user:view not always respected when navigating to a users course grade report


System information

   
Affected software PHP

Description

di Michael Hawkins. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.Severity/Risk:MinorVersions affected:3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versionsVersions fixed:3.11.5, 3.10.9 and 3.9.12Reported by:Deds CastilloCVE identifier:CVE-2022-0334Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=431102&parent=1734816

Standar resources

Property Value
CVE CVE-2022-0334.

Version history

Version Comments Date
1.0 Advisory issued 2022-05-17
Ministerio de Defensa
CNI
CCN
CCN-CERT