-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 2.6.0, <= 2.6.2 | 2.7.0 |
| moodle/moodle | composer | >= 2.5.0, <= 2.5.5 | 2.5.6 |
| moodle/moodle | composer | >= 2.4.0, <= 2.4.9 | 2.4.10 |
The vulnerability stems from student identifiers being present in HTML output during blind-marked assignments. Key evidence includes: