Exposure of Resource to Wrong Sphere Affecting moodle/moodle package, versions >=2.7, <2.7.20>=3.0, <3.0.10>=3.1, <3.1.6>=3.2, <3.2.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.11% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-MOODLEMOODLE-6673175
  • published24 Apr 2024
  • disclosed13 May 2022
  • creditUnknown

Introduced: 13 May 2022

CVE-2017-7490  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade moodle/moodle to version 2.7.20, 3.0.10, 3.1.6, 3.2.3 or higher.

Overview

moodle/moodle is a learning platform.

Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere due to a missing capability check in the blog search functionality. An attacker can perform unauthorized searches of arbitrary blogs by constructing and submitting a full URL directly.

References