CVE-2024-43427

LOW

Moodle - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.

Scores

CVSS v3 3.7
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (2)
moodle/moodle < 4.1.12
moodle/moodle 4.4.0 - 4.4.2Packagist
Published Nov 11, 2024
Tracked Since Feb 18, 2026