Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Moodle 权限许可和访问控制问题漏洞
Vulnerability Description
Moodle是澳大利亚马丁-多基马(Martin Dougiamas)博士开发的一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle 1.9.15之前的1.9.x版本、2.0.6之前的2.0.x版本以及2.1.3之前的2.1.x版本中的MNET认证功能中存在漏洞。远程认证用户可利用该漏洞通过使用Login As功能结合远程MNET单点登录功能的Mahara站点连接,冒充其他用户账号。
CVSS Information
N/A
Vulnerability Type
N/A