PT-2021-2241 · Moodle+1 · Moodle+1

Juan Segarra Montesinos

·

Published

2021-01-12

·

Updated

2024-03-06

·

CVE-2021-20184

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.10.1 Moodle versions prior to 3.9.4 Moodle versions prior to 3.8.7
Description The issue is related to insufficient capability checks in some grade-related web services, allowing students to view other students' grades. This is due to flaws in access control within the "Gradebook" module of the Moodle virtual learning environment. Exploitation of this issue can allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 3.10.1, update to version 3.10.1 or later. For versions prior to 3.9.4, update to version 3.9.4 or later. For versions prior to 3.8.7, update to version 3.8.7 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1050
ALT-PU-2021-1098
ALT-PU-2022-1641
BDU:2021-01193
BIT-MOODLE-2021-20184
CVE-2021-20184
GHSA-MM73-86F9-5X5C

Affected Products

Alt Linux
Moodle