CVE-2023-28336
published 2023-03-23CVE-2023-28336: Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.74%
50.5th percentile
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| moodle | moodle | < 3.9.20 | 3.9.20 |
| moodle | moodle | < 3.11.13 | 3.11.13 |
| moodle | moodle | < 4.0.7 | 4.0.7 |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | >= 0 < 3.9.20 | 3.9.20 |
| moodle | moodle | >= 3.11.0 < 3.11.13 | 3.11.13 |
| moodle | moodle | >= 4.0.0 < 4.0.7 | 4.0.7 |
| moodle | moodle | >= 4.1.0 < 4.1.2 | 4.1.2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moodle may allow teachers to access the names of users they could not otherwise access
ghsa·2023-03-23
CVE-2023-28336 [MEDIUM] CWE-200 Moodle may allow teachers to access the names of users they could not otherwise access
Moodle may allow teachers to access the names of users they could not otherwise access
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
OSV
Moodle may allow teachers to access the names of users they could not otherwise access
osv·2023-03-23
CVE-2023-28336 [MEDIUM] Moodle may allow teachers to access the names of users they could not otherwise access
Moodle may allow teachers to access the names of users they could not otherwise access
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
OSV
CVE-2023-28336: Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access
osv·2023-03-23·CVSS 4.3
CVE-2023-28336 [MEDIUM] CVE-2023-28336: Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2179426https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/https://moodle.org/mod/forum/discuss.php?d=445068https://bugzilla.redhat.com/show_bug.cgi?id=2179426https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/https://moodle.org/mod/forum/discuss.php?d=445068
2023-03-23
Published