First published: Fri Jan 21 2022(Updated: )
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/moodle | <3.11.5 | 3.11.5 |
redhat/moodle 3.10.9 and moodle | <3.9.12 | 3.9.12 |
Moodle | <=3.8.9 | |
Moodle | >=3.9.0<=3.9.11 | |
Moodle | >=3.10.0<3.10.9 | |
Moodle | >=3.11.0<3.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0334 is classified as a medium severity vulnerability due to insufficient capability checks.
To fix CVE-2022-0334, upgrade Moodle to version 3.11.5 or 3.9.12, or ensure you are running a version beyond the specified vulnerable versions.
CVE-2022-0334 affects Moodle versions 3.11.0 to 3.11.4, 3.10.0 to 3.10.8, and 3.9.0 to 3.9.11.
Yes, CVE-2022-0334 can potentially lead to unauthorized users accessing grade reports they are not permitted to view.
Currently, there is no specific workaround for CVE-2022-0334; the recommended action is to update to a fixed version.