Skip to main content

Exposure of Resource to Wrong Sphere

CVE-2023-1402

Severity Medium
Score 4.3/10

Summary

The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. This issue affects the moodle versions through 3.9.19, 3.10.0-beta through 3.11.12, 4.0.0-beta through 4.0.6 and 4.1.0-beta through 4.1.1.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Advisory Timeline

  • Published