PT-2022-2727 · Moodle+2 · Moodle+2

Catalina

·

Published

2022-04-21

·

Updated

2024-03-06

·

CVE-2022-30598

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw was found in Moodle where global search results could include author information on some activities where a user may not otherwise have access to it. The vulnerability is related to insufficient protection of internal data in the core search class, allowing a remote attacker to gain unauthorized access to protected information. Exploitation of the vulnerability may allow an attacker to obtain confidential information in the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2502
ALT-PU-2022-2553
BDU:2022-03231
BIT-MOODLE-2022-30598
CVE-2022-30598
GHSA-FJ6P-G234-RRV3

Affected Products

Alt Linux
Moodle
Red Os