CVE-2024-38273

MEDIUM

Moodle 4.1.0-4.1.10 and 4.4.0-beta - Improper Access Control in BigBlueButton Join URL

Title source: llm
STIX 2.1

Description

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Scores

CVSS v3 5.4
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (5)
fedoraproject/fedora 39
fedoraproject/fedora 40
moodle/moodle 4.4.0
moodle/moodle 4.1.0 - 4.1.11
moodle/moodle 4.4.0-beta - 4.4.1Packagist
Published Jun 18, 2024
Tracked Since Feb 18, 2026