CVE-2023-28336: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
Affected products
- Fedoraproject Fedora: version 36 only
- Moodle Moodle: after 3.9.0, before 3.9.20 (fixed in 3.9.20); after 3.11.0, before 3.11.13 (fixed in 3.11.13); after 4.0.0, before 4.0.7 (fixed in 4.0.7); version 3.9.0 only; version 3.11.0 only; version 4.0.0 only; …
Published 2023-03-23. Last modified 2026-06-17.