CVE-2024-38273

MEDIUM4.3EPSS 0.20%

Moodle BigBlueButton web service leaks meeting joining information

發布日:2024/6/18修改日:2025/8/8
也稱為:GHSA-x29x-qwvx-fxr2BIT-moodle-2024-38273

描述

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(11)