cbcvebase.
CVE-2022-0984
published 2022-04-29

CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria…

PriorityP419medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.53%
41.5th percentile
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

Affected

11 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
moodlemoodle
moodlemoodle>= 0 < 3.9.133.9.13
moodlemoodle>= 3.10.0 < 3.10.103.10.10
moodlemoodle>= 3.10.0 < 3.10.103.10.10
moodlemoodle>= 3.11.0 < 3.11.63.11.6
moodlemoodle>= 3.11.0 < 3.11.63.11.6
moodlemoodle>= 3.9.0 < 3.9.133.9.13
redhatenterprise_linux

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.3MEDIUM
cisa8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.