Exposure of Resource to Wrong Sphere
CVE-2023-1402
Summary
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. This issue affects the moodle versions through 3.9.19, 3.10.0-beta through 3.11.12, 4.0.0-beta through 4.0.6 and 4.1.0-beta through 4.1.1.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-668 - Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Advisory Timeline
- Published