First published: Tue Mar 15 2022(Updated: )
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. Versions affected: 3.11 to 3.11.5, 3.10 to 3.10.9, 3.9 to 3.9.12 and earlier unsupported versions References: <a href="http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72972">http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72972</a>
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <3.9.13 | 3.9.13 |
composer/moodle/moodle | >=3.10.0<3.10.10 | 3.10.10 |
composer/moodle/moodle | >=3.11.0<3.11.6 | 3.11.6 |
composer/moodle/moodle | >=3.9<3.9.13 | 3.9.13 |
redhat/moodle | <3.11.6 | 3.11.6 |
redhat/moodle | <3.10.10 | 3.10.10 |
redhat/moodle | <3.9.13 | 3.9.13 |
Moodle | <3.9.13 | |
Moodle | >=3.10.0<3.10.10 | |
Moodle | >=3.11.0<3.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0985 has been classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2022-0985, upgrade Moodle to versions 3.9.13, 3.10.10, or 3.11.6 or later.
CVE-2022-0985 affects Moodle versions 3.11 to 3.11.5, 3.10 to 3.10.9, 3.9 to 3.9.12, and earlier unsupported versions.
CVE-2022-0985 involves insufficient capability checks allowing users with moodle/site:uploadusers to delete users without the required moodle/user:delete capability.
CVE-2022-0985 could allow unauthorized users to delete accounts, undermining user management controls within Moodle.