CVE-2024-34009

HIGH

Moodle 4.3.0-4.3.3 - Unauthenticated ReCAPTCHA Bypass on Login Page

Title source: llm
STIX 2.1

Description

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
moodle/moodle 4.3.0 - 4.3.4
moodle/moodle 4.3.0 - 4.3.4Packagist
Published May 31, 2024
Tracked Since Feb 18, 2026