5.3
CVE-2025-32045
- EPSS 0.18%
- Veröffentlicht 25.04.2025 14:43:54
- Zuletzt bearbeitet 29.04.2025 13:52:28
- Quelle patrick@puiterwijk.org
- CVE-Watchlists
- Unerledigt
Moodle: hidden grades shown to users without permission on some grade reports
Hidden grades are shown to users without permission on some grade reports
A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.
Mögliche Gegenmaßnahme
Moodle Server: Update to a patched version.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Collection URLhttp://git.moodle.org/gw?p=moodle.git
≫
Paket
moodle
Default Statusunaffected
Version
4.5.3
Status
affected
Version
4.4.7
Status
affected
Version
4.3.11
Status
affected
Version
4.1.17
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemMoodle
≫
Produkt
Moodle Server
Version
< 4.1.0
Version
>= 4.5.0, < 4.5.3
Version
>= 4.4.0, < 4.4.7
Version
>= 4.3.0, < 4.3.11
Version
>= 4.1.0, < 4.1.17
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.395 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| patrick@puiterwijk.org | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.