A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
2025-10-23T12:15:31.747
2025-11-14T19:39:08.987
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | < 4.1.21 | Yes |
| Application | moodle | moodle | < 4.4.11 | Yes |
| Application | moodle | moodle | < 4.5.7 | Yes |
| Application | moodle | moodle | < 5.0.3 | Yes |