moodle: Some users can delete audiences of other reports
Moderate severity
GitHub Reviewed
Published
Nov 18, 2024
to the GitHub Advisory Database
•
Updated Nov 18, 2024
Package
Affected versions
< 4.1.14
>= 4.2.0, < 4.2.11
>= 4.3.0, < 4.3.8
>= 4.4.0, < 4.4.4
Patched versions
4.1.14
4.2.11
4.3.8
4.4.4
Description
Published by the National Vulnerability Database
Nov 18, 2024
Published to the GitHub Advisory Database
Nov 18, 2024
Reviewed
Nov 18, 2024
Last updated
Nov 18, 2024
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
References