
We found results for “”
CVE-2022-0334
Good to know:

Date: January 25, 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Top Fix

Upgrade Version
Upgrade to version moodle/moodle - v3.6.5;moodle/moodle - dev-MOODLE_39_STABLE;moodle/moodle - v3.7.1;moodle/moodle - v3.5.2;moodle/moodle - v3.11.2;moodle/moodle - v3.8.5;moodle/moodle - v3.10.6;moodle/moodle - v3.3.8;moodle/moodle - v3.8.1;moodle/moodle - v3.1.14;moodle/moodle - v3.6.0-beta;moodle/moodle - v3.4.5;moodle/moodle - v3.5.7;moodle/moodle - v3.7.8;moodle/moodle - v3.9.9;moodle/moodle - v3.7.0-rc2;covex-nn/moodle - v2.6.0.5;covex-nn/moodle - v2.9.1.0;covex-nn/moodle - v2.5.0.0;covex-nn/moodle - v2.4.3.1;covex-nn/moodle - v2.8.0.0;acosf/archersys - 3.5;acosf/archersys - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |