Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 4.5, <= 4.5.3
- >= 4.4, <= 4.4.7
- >= 4.3, <= 4.3.11
- >= 4.1, <= 4.1.17
An authorization flaw has been identified in Moodle, specifically in versions 4.5 prior to 4.5.4, 4.4 prior to 4.4.8, 4.3 prior to 4.3.12, 4.1 prior to 4.1.18, and earlier unsupported versions. The vulnerability allows users to access cohort data they are not authorized to retrieve, indicating an issue of incorrect authorization. This flaw could be exploited by users to fetch unauthorized cohort information.
Exploitation of this vulnerability could lead to unauthorized access to cohort data, allowing users to view information they are not entitled to.
Users can upgrade to Moodle versions 4.5.4, 4.4.8, 4.3.12 or 4.1.18 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.