A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
History

Wed, 20 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 10:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Title Moodle: idor when accessing list of course badges
Weaknesses CWE-284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2024-11-20T10:25:58.315Z

Updated: 2024-11-20T19:16:12.331Z

Reserved: 2024-10-09T12:15:07.577Z

Link: CVE-2024-48899

cve-icon Vulnrichment

Updated: 2024-11-20T19:16:03.038Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-20T11:15:05.563

Modified: 2024-11-21T13:57:24.187

Link: CVE-2024-48899

cve-icon Redhat

No data.