CVE-2023-28336

MEDIUM

Moodle < 3.9.20 - Information Disclosure

Title source: rule

Description

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200 CWE-668
Status published

Affected Products (8)

moodle/moodle < 3.9.20
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
fedoraproject/fedora
moodle/moodle < 4.1.2Packagist

Timeline

Published Mar 23, 2023
Tracked Since Feb 18, 2026