GHSA-4c5g-w3gf-rf4f

Suggest an improvement
Source
https://github.com/advisories/GHSA-4c5g-w3gf-rf4f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c5g-w3gf-rf4f/GHSA-4c5g-w3gf-rf4f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4c5g-w3gf-rf4f
Aliases
  • CVE-2014-3546
Published
2022-05-13T01:12:40Z
Modified
2024-12-07T05:39:25.086310Z
Summary
Moodle allows attackers to obtain username and course information
Details

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requirements in (1) notes/index.php and (2) user/edit.php, which allows remote attackers to obtain potentially sensitive username and course information via a modified URL.

Database specific
{
    "nvd_published_at": "2014-07-29T11:10:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-24T21:20:16Z"
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.11

Affected versions

v2.*

v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.3.10
v2.3.11
v2.4.0-rc1
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.4.10

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.0
Fixed
2.5.7

Affected versions

v2.*

v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.0
Fixed
2.6.4

Affected versions

v2.*

v2.6.0
v2.6.1
v2.6.2
v2.6.3

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.7.0
Fixed
2.7.1

Affected versions

v2.*

v2.7.0