Moderate severityNVD Advisory· Published Apr 29, 2022· Updated Aug 2, 2024
CVE-2022-0985
CVE-2022-0985
Description
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 3.11.0, < 3.11.6 | 3.11.6 |
moodle/moodlePackagist | >= 3.10.0, < 3.10.10 | 3.10.10 |
moodle/moodlePackagist | >= 3.9, < 3.9.13 | 3.9.13 |
Affected products
3- osv-coords2 versions
< 3.9.13+ 1 more
- (no CPE)range: < 3.9.13
- (no CPE)range: >= 3.11.0, < 3.11.6
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-6q9g-3vfq-q2qjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0985ghsaADVISORY
- bugzilla.redhat.com/show_bug.cgighsax_refsource_MISCWEB
- github.com/moodle/moodle/commit/addd4f894d8173ec8ff0ae2212d51a1977e7bcadghsaWEB
News mentions
0No linked articles in our index yet.