CVE-2022-30598Sensitive Information Exposure in Moodle

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 19

Description

A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDmoodle/moodle3.93.9.14+3
Packagistmoodle/moodle4.04.0.1+3
CVEListV5moodle/moodleAffects : 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions

Also affects: Fedora 34, 35, 36, Enterprise Linux 8.0

Patches

🔴Vulnerability Details

4
OSV
Exposure of Sensitive Information in moodle2022-05-19
GHSA
Exposure of Sensitive Information in moodle2022-05-19
OSV
CVE-2022-30598: A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access2022-05-18
CVEList
CVE-2022-30598: A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access2022-05-18
CVE-2022-30598 — Sensitive Information Exposure | cvebase