← Back

CVE-2022-0984

nvd nist
Published: Apr 29, 2022Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

Affected (7)

1 product
Moodle
1 product
Fedora
1 product
Enterprise Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.10.0 to 3.10.10
From 3.11.0 to 3.11.6
From 3.9.0 to 3.9.13
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Version 36
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

References (2)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.