cbcvebase.
CVE-2023-28336
published 2023-03-23

CVE-2023-28336: Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.74%
50.5th percentile
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

Affected

13 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
moodlemoodle< 3.9.203.9.20
moodlemoodle< 3.11.133.11.13
moodlemoodle< 4.0.74.0.7
moodlemoodle
moodlemoodle
moodlemoodle
moodlemoodle
moodlemoodle
moodlemoodle>= 0 < 3.9.203.9.20
moodlemoodle>= 3.11.0 < 3.11.133.11.13
moodlemoodle>= 4.0.0 < 4.0.74.0.7
moodlemoodle>= 4.1.0 < 4.1.24.1.2

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.