CVE-2023-5543: Moodle: duplicating a bigbluebutton activity assigns the same meeting id
Published Oct 12, 2023
·Updated
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
Affected Software
8 affected componentsFixes available
redhat/moodle<4.2.3
4.2.3
redhat/moodle<4.1.6
4.1.6
redhat/moodle<4.0.11
4.0.11
Moodle moodle>=4.0.0<4.0.11
Moodle moodle>=4.1.0<4.1.6
Moodle moodle>=4.2.0<4.2.3
Fedoraproject Extra Packages For Enterprise Linux=7.0
Fedoraproject Fedora=38
Remediation
Patch Available
Patch Available
Event History
Nov 9, 2023
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-5543.
2
What is the severity of CVE-2023-5543?
The severity of CVE-2023-5543 is low with a severity value of 3.3.
3
How does CVE-2023-5543 affect Moodle?
CVE-2023-5543 affects Moodle by allowing the duplicated BigBlueButton activity to have the same meeting ID as the original, potentially providing unintended access.
4
Which versions of Moodle are affected by CVE-2023-5543?
Versions up to and exclusive of 4.0.11, 4.1.6, and 4.2.3 of Moodle are affected by CVE-2023-5543.
5
How can I fix CVE-2023-5543?
To fix CVE-2023-5543, update Moodle to version 4.0.11, 4.1.6, or 4.2.3, depending on the branch you are using.