← Back to CVEs
CVE-2024-48899
MEDIUM4.3
Description
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
CVE Details
CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published11/20/2024
Last Modified6/2/2025
Sourcenvd
Honeypot Sightings0
Affected Products
moodle:moodle
Weaknesses (CWE)
CWE-284CWE-639
References
https://bugzilla.redhat.com/show_bug.cgi?id=2318819(patrick@puiterwijk.org)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.