CVE-2023-23923

CVSS V2 None CVSS V3 None
Description
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
Overview
  • CVE ID
  • CVE-2023-23923
  • Assigner
  • patrick@puiterwijk.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-17T20:15:11
  • Last Modified Date
  • 2023-02-28T19:17:27
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 1 OR 3.9.0 3.9.19
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 1 OR 3.11.0 3.11.12
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 1 OR 4.0.0 4.0.6
cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 07:57:14 Added to TrackCVE
2023-04-17 07:57:16 Weakness Enumeration new