← Volver a CVEs
CVE-2024-48899
MEDIUM4.3
Descripcion
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Detalles CVE
Puntuacion CVSS v3.14.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado11/20/2024
Ultima modificacion6/2/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
moodle:moodle
Debilidades (CWE)
CWE-284CWE-639
Referencias
https://bugzilla.redhat.com/show_bug.cgi?id=2318819(patrick@puiterwijk.org)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.