Vulnerability Bulletins

MSA-22-0012: Global search results reveal authors of content unexpectedly for some activities


System information

   
Affected software PHP

Description

by Michael Hawkins. Global search results could include author information on some activities where a user may not otherwise have access to it.Severity/Risk:MinorVersions affected:4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versionsVersions fixed:4.0.1, 3.11.7, 3.10.11 and 3.9.14Reported by:CatalinaCVE identifier:CVE-2022-30598Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71623Tracker issue:MDL-71623 Global

More info:

https://moodle.org/mod/forum/discuss.php?d=434580&parent=1748724

Standar resources

Property Value
CVE CVE-2022-30598.

Version history

Version Comments Date
1.0 Advisory issued 2022-05-18
Ministerio de Defensa
CNI
CCN
CCN-CERT