{"id":"GHSA-h9w8-4376-j344","summary":"Moodle does not properly validate module instance id","details":"Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.","aliases":["CVE-2006-4936"],"modified":"2024-02-12T16:56:53.307305Z","published":"2022-05-01T07:23:24Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-02-12T16:29:26Z","nvd_published_at":"2006-09-23T00:07:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4936"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/0f69811d980002709668a2001477a811bfee4bab"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://web.archive.org/web/20061230195936/http://docs.moodle.org/en/Release_notes#Moodle_1.6.2"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h9w8-4376-j344/GHSA-h9w8-4376-j344.json"}}],"schema_version":"1.9.0"}