CVE-2024-43429

MEDIUM5.3EPSS 0.30%

Moodle has user information visibility control issues in gradebook reports

發布日:2024/11/11修改日:2025/5/2
也稱為:GHSA-c767-4whh-v7rwBIT-moodle-2024-43429

描述

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

參考連結(5)