Description
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=391035
Scores
CVSS v3
4.3
EPSS
0.0074
EPSS Percentile
49.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-573
Status
published
Products (1)
moodle/moodle
3.5.0 - 3.5.7
Published
Mar 19, 2021
Tracked Since
Feb 18, 2026