First published: Thu Oct 12 2023(Updated: )
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <4.3.0-rc2 | 4.3.0-rc2 |
Moodle Moodle | =4.2.2 | |
Fedoraproject Extra Packages For Enterprise Linux | =7.0 | |
Fedoraproject Fedora | =38 | |
redhat/moodle | <4.2.3 | 4.2.3 |
=4.2.2 | ||
=7.0 | ||
=38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-5542.
The severity of CVE-2023-5542 is medium.
Software versions up to 4.2.3 of Moodle and up to 4.3.0-rc2 of moodle/moodle are affected by CVE-2023-5542.
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
Yes, you can find more information about CVE-2023-5542 at the following references: - [Moodle Git Repository](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79213) - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2243441) - [Moodle Forum Discussion](https://moodle.org/mod/forum/discuss.php?d=451583)