Insufficient capability checks made it possible to disable badges a user does not have permission to access.
2025-02-24T20:15:33.933
2025-08-07T00:06:02.483
Analyzed
CVSSv3.1: 3.1 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | < 4.1.16 | Yes |
| Application | moodle | moodle | < 4.3.10 | Yes |
| Application | moodle | moodle | < 4.4.6 | Yes |
| Application | moodle | moodle | < 4.5.2 | Yes |