Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1703 Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
Github GHSA Github GHSA GHSA-c5hf-mc85-2hx4 Missing authorization in Moodle
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-02T23:47:43.231Z

Reserved: 2022-03-15T00:00:00

Link: CVE-2022-0984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-29T17:15:20.237

Modified: 2024-11-21T06:39:47.920

Link: CVE-2022-0984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.