MEDIUM
Moodle: idor when accessing list of course badges
Published Nov 20, 2024
5.3
MEDIUMCVSS 4.0
EPSS 0.31%
Description
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://bugzilla.redhat.com/show_bug.cgi?id=2318819 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-r4xr-m393-778m Advisory
- https://github.com/moodle/moodle/commit/07ad4b8ebc715056056e01f2175820bfce6b290f
- https://moodle.org/mod/forum/discuss.php?d=462878#p1858337
- https://nvd.nist.gov/vuln/detail/CVE-2024-48899
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2318819 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-r4xr-m393-778m | Advisory | |
| https://github.com/moodle/moodle/commit/07ad4b8ebc715056056e01f2175820bfce6b290f | ||
| https://moodle.org/mod/forum/discuss.php?d=462878#p1858337 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-48899 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published Nov 20, 2024
Updated Nov 20, 2024
Reserved Oct 9, 2024
Link CVE-2024-48899
CISA Vulnrichment
GHSA-R4XR-M393-778M Updated Nov 20, 2024