CVE-2024-25983

MEDIUM5.3EPSS 0.24%

Authorization Bypass in moodle

發布日:2024/2/19修改日:2025/1/23
也稱為:GHSA-9r26-5w88-qhp9BIT-moodle-2024-25983

描述

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(8)