CVE-2022-0984Incorrect Authorization in Moodle

Severity
4.3MEDIUMNVD
CISA8.8
EPSS
0.2%
top 59.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateMay 25

Description

Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDmoodle/moodle3.9.03.9.13+2
Packagistmoodle/moodle3.11.03.11.6+2
CVEListV5moodle/moodlemoodle 3.11.6, moodle 3.10.10, moodle 3.9.13

Also affects: Fedora 34, 35, 36, Enterprise Linux 7.0

🔴Vulnerability Details

4
GHSA
Missing authorization in Moodle2022-04-30
OSV
Missing authorization in Moodle2022-04-30
OSV
CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field crite2022-04-29
CVEList
CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field crite2022-04-29

📋Vendor Advisories

1
CISA
Adobe Flash Player and AIR Use-After-Free Vulnerability2022-05-25
CVE-2022-0984 — Incorrect Authorization in Moodle | cvebase