CVE-2023-28336: Moodle: teacher can access names of users they do not have permission to access
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28336?
CVE-2023-28336 is a vulnerability in Moodle that allows teachers to access the names of users they should not have access to.
How severe is CVE-2023-28336?
CVE-2023-28336 has a severity rating of 4.3, which is considered medium.
Which versions of Moodle are affected by CVE-2023-28336?
CVE-2023-28336 affects Moodle versions 3.9.0 to 3.9.20, 3.11.0 to 3.11.13, 4.0.0 to 4.0.7, 4.1.0, and 4.1.1.
How can I fix CVE-2023-28336?
To fix CVE-2023-28336, it is recommended to upgrade Moodle to a version that includes the necessary security patches.
Where can I find more information about CVE-2023-28336?
More information about CVE-2023-28336 can be found at the following references: [Reference 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/) and [Reference 2](https://moodle.org/mod/forum/discuss.php?d=445068).