PT-2022-2038 · Moodle+2 · Moodle+2

Tej Rathi

·

Published

2022-03-14

·

Updated

2024-03-06

·

CVE-2022-0985

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The issue is related to insufficient capability checks in Moodle, which could allow users with the moodle/site:uploadusers capability to delete users without having the necessary moodle/user:delete capability. This could potentially be exploited by a remote attacker to delete arbitrary users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Incorrect Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1476
ALT-PU-2022-1641
ALT-PU-2022-2450
BDU:2022-01637
BIT-MOODLE-2022-0985
CVE-2022-0985
GHSA-6Q9G-3VFQ-Q2QJ

Affected Products

Alt Linux
Moodle
Red Os