CVE-2024-48899

MEDIUM

Moodle < 4.4.4 - Improper Access Control

Title source: rule
STIX 2.1

Description

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

References (1)

Core 1
Core References
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2318819

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-639
Status published
Products (2)
moodle/moodle 4.4.0 - 4.4.4
moodle/moodle 4.4.0-beta - 4.4.3Packagist
Published Nov 20, 2024
Tracked Since Feb 18, 2026