Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2064118 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2022-04-29 10:15
Updated : 2022-05-10 11:57
NVD link : CVE-2022-0984
Mitre link : CVE-2022-0984
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
redhat
- enterprise_linux
moodle
- moodle
fedoraproject
- fedora