CVE-2024-43435

MEDIUM

Moodle < 4.1.12 - Improper Condition Check

Title source: rule
STIX 2.1

Description

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (2)
moodle/moodle < 4.1.12
moodle/moodle 4.4.0 - 4.4.2Packagist
Published Nov 11, 2024
Tracked Since Feb 18, 2026