-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing access control checks in group override handling. The override form (override_form.php) would be responsible for presenting group options, and the update logic (lib.php) would handle persistence. Without proper validation of group membership or 'accessallgroups' capability in these components, teachers could manipulate unrelated group overrides. This aligns with the CWE-284 classification and Moodle's module structure where assignment overrides are managed.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 3.7.0, < 3.7.1 | 3.7.1 |
| moodle/moodle | composer | >= 3.6.0, < 3.6.5 | 3.6.5 |
| moodle/moodle | composer |
| < 3.5.7 |
| 3.5.7 |
Ongoing coverage of React2Shell