-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly mentions a missing permission check in the web service for fetching enrolled courses. In Moodle's architecture:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 3.10.0, < 3.10.2 | 3.10.2 |
| moodle/moodle | composer | >= 3.9.0, < 3.9.5 | 3.9.5 |
| moodle/moodle | composer | >= 3.8.0, < 3.8.8 | 3.8.8 |
| moodle/moodle | composer | < 3.5.17 | 3.5.17 |
KEV Misses 88% of Exploited CVEs- Get the report