The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-2009 The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Github GHSA Github GHSA GHSA-2m72-m5cw-3g9h Missing permission check in Moodle
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-03T17:37:23.308Z

Reserved: 2020-12-17T00:00:00

Link: CVE-2021-20283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-15T22:15:13.373

Modified: 2024-11-21T05:46:16.780

Link: CVE-2021-20283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.