-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing capability validation in the parent context during category movement operations. The patch adds new checks in update_categories() for 'moodle/category:manage' capability in the destination parent context when modifying the 'parent' field. The pre-patch version only validated capabilities in the original category context, not the new parent context. The test case added in externallib_test.php demonstrates this vulnerability by attempting unauthorized category movement that should throw an exception after proper checks are implemented.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | < 4.3.0-rc2 | 4.3.0-rc2 |
Ongoing coverage of React2Shell