← back
CVE-2021-20283

CVE-2021-20283

EPSS 1.1%CWE-863
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Affected products
n/a · moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →