Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The core_grade component in Moodle through 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly consider the existence of hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role and reading the Gradebook Overview report.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Moodle ‘Gradebook’信息泄露漏洞
Vulnerability Description
Moodle是澳大利亚马丁-多基马(Martin Dougiamas)博士开发的一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle 2.1.10之前的版本,2.3.7之前的2.3.x版本,2.4.4之前的2.4.x版本中的core_grade组件中存在漏洞,该漏洞源于程序没有正确考虑是否存在隐藏的成绩。远程经过授权的用户可通过学生角色并读取Gradebook Overview报告利用该漏洞获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A