CVE-2024-48898

MEDIUM

Moodle < 4.1.14 - Missing Authorization in Audience Deletion

Title source: llm
STIX 2.1

Description

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

References (1)

Core 1
Core References
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2318820

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
moodle/moodle < 4.1.14
moodle/moodle 0 - 4.1.14Packagist
Published Nov 18, 2024
Tracked Since Feb 18, 2026