5.3

CVE-2022-30597

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 3.9 < 3.9.14
Moodle ≫ Moodle Version >= 3.10 < 3.10.11
Moodle ≫ Moodle Version >= 3.11 < 3.11.7
Moodle ≫ Moodle Version 4.0.0 Update -
Redhat ≫ Enterprise Linux Version 8.0 SwEdition -
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.31% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-472 External Control of Assumed-Immutable Web Parameter

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OGF35EN5K2R6X3NTY3XPZSJ3UDASMXI6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PIMSIRKCFLIC646K4GMUSZU7THOUVPAJ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCTWSE3JDMSYL7DPCMXMMJEXZSS6VIA5/
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74318
Patch
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2083585
Third Party Advisory
Issue Tracking
https://moodle.org/mod/forum/discuss.php?d=434579
Vendor Advisory