CVE-2023-5551
published 2023-11-09CVE-2023-5551: Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
PriorityP49low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.28%
19.8th percentile
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | < 3.9.24 | 3.9.24 |
| moodle | moodle | >= 0 < 3.9.24 | 3.9.24 |
| moodle | moodle | >= 3.10.0 < 3.11.17 | 3.11.17 |
| moodle | moodle | >= 3.11.0 < 3.11.17 | 3.11.17 |
| moodle | moodle | >= 4.0.0 < 4.0.11 | 4.0.11 |
| moodle | moodle | >= 4.0.0 < 4.0.11 | 4.0.11 |
| moodle | moodle | >= 4.1.0 < 4.1.6 | 4.1.6 |
| moodle | moodle | >= 4.1.0 < 4.1.6 | 4.1.6 |
| moodle | moodle | >= 4.2.0 < 4.2.3 | 4.2.3 |
| moodle | moodle | >= 4.2.0 < 4.2.3 | 4.2.3 |
| moodle | moodle | >= 4.3.0-beta < 4.3.0-rc2 | 4.3.0-rc2 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
osv·2023-11-09
CVE-2023-5551 [LOW] Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
OSV
CVE-2023-5551: Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups
osv·2023-11-09·CVSS 3.3
CVE-2023-5551 [LOW] CVE-2023-5551: Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
GHSA
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
ghsa·2023-11-09
CVE-2023-5551 [LOW] CWE-200 Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79310https://bugzilla.redhat.com/show_bug.cgi?id=2243453https://moodle.org/mod/forum/discuss.php?d=451592http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79310https://bugzilla.redhat.com/show_bug.cgi?id=2243453https://moodle.org/mod/forum/discuss.php?d=451592
2023-11-09
Published