cbcvebase.
CVE-2022-0984
published 2022-04-29

CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

Affected

11 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
moodlemoodle
moodlemoodle>= 0 < 3.9.133.9.13
moodlemoodle>= 3.10.0 < 3.10.103.10.10
moodlemoodle>= 3.10.0 < 3.10.103.10.10
moodlemoodle>= 3.11.0 < 3.11.63.11.6
moodlemoodle>= 3.11.0 < 3.11.63.11.6
moodlemoodle>= 3.9.0 < 3.9.133.9.13
redhatenterprise_linux

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv4.3MEDIUM
cisa8.8HIGH