CVE-2022-0984

Source
https://cve.org/CVERecord?id=CVE-2022-0984
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0984.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-0984
Aliases
Downstream
Published
2022-04-29T17:15:20.237Z
Modified
2026-02-08T22:19:52.913449Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

References

Affected packages

Git / github.com/moodle/moodle

Affected versions

v3.*
v3.10.0
v3.10.1
v3.10.2
v3.10.3
v3.10.4
v3.10.5
v3.10.6
v3.10.7
v3.10.8
v3.10.9
v3.11.0
v3.11.0-beta
v3.11.0-rc1
v3.11.0-rc2
v3.11.1
v3.11.2
v3.11.3
v3.11.4
v3.11.5
v3.9.0
v3.9.1
v3.9.10
v3.9.11
v3.9.12
v3.9.2
v3.9.3
v3.9.4
v3.9.5
v3.9.6
v3.9.7
v3.9.8
v3.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0984.json"