First published: Tue May 10 2022(Updated: )
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.9<3.9.14 | 3.9.14 |
composer/moodle/moodle | >=3.10<3.10.11 | 3.10.11 |
composer/moodle/moodle | >=3.11<3.11.7 | 3.11.7 |
composer/moodle/moodle | >=4.0<4.0.1 | 4.0.1 |
redhat/moodle | <4.0.1 | 4.0.1 |
redhat/moodle | <3.11.7 | 3.11.7 |
redhat/moodle | <3.10.11 | 3.10.11 |
redhat/moodle | <3.9.14 | 3.9.14 |
Moodle | >=3.9<3.9.14 | |
Moodle | >=3.10<3.10.11 | |
Moodle | >=3.11<3.11.7 | |
Moodle | =4.0.0 | |
Red Hat Enterprise Linux | =8.0 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-30597 is classified as moderate due to the exposure of user description fields that should be hidden.
To fix CVE-2022-30597, upgrade to Moodle versions 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
CVE-2022-30597 affects Moodle versions 4.0, 3.11, 3.10, 3.9, and earlier unsupported versions.
Yes, there are patches available for CVE-2022-30597 in the latest Moodle releases.
CVE-2022-30597 exposes the user description field, which is not properly hidden when set as a hidden user field.