ZeroHour

CVE-2022-0334

CVSS 3.1
4.3 medium
EPSS
<1%p52
Published
()
Modified
Description

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

Vendors
moodle
Products
moodle
Weakness
CWE-863, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.