A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| moodle/moodle(Packagist) | 0 | 4.1.13 | N/A |
| moodle/moodle(Packagist) | 4.2.0-beta | 4.2.10 | N/A |
| moodle/moodle(Packagist) | 4.3.0-beta | 4.3.7 | N/A |
| moodle/moodle(Packagist) | 4.4.0-beta | 4.4.3 | N/A |
CVSS Metrics