CVE-2024-43435

MEDIUM

Moodle < 4.1.12 and 4.4.0-4.4.2 - Insufficient Capability Check in Glossary Restore

Title source: llm
STIX 2.1

Description

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

References (2)

Core 2
Core References
Permissions Required issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2304263

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (2)
moodle/moodle < 4.1.12
moodle/moodle 4.4.0 - 4.4.2Packagist
Published Nov 11, 2024
Tracked Since Feb 18, 2026