Untriaged
Moodle: possible to set the preferred "start page" of other users
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
Affected products
moodle
- <3.11.12
- <4.0.6
- <3.9.19
- <4.1.1
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>