The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moodle/moodle(Packagist) | 0 | 3.9.19 | N/A |
| moodle/moodle(Packagist) | 3.10.0 | 3.11.12 | N/A |
| moodle/moodle(Packagist) | 4.0.0-beta | 4.0.6 | N/A |
| moodle/moodle(Packagist) | 4.1.0-beta | 4.1.1 | N/A |
CVSS Metrics