CVE-2024-25979: Msa-24-0002: forum search accepted random parameters in its url
MSA-24-0002: Forum search accepted random parameters in its URL
Description: The URL parameters accepted by forum search were not limited to the allowed parameters. Issue summary: Forum search accepted random parameters in its URL Severity/Risk: Minor Versions affected: 4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versions Versions fixed: 4.3.3, 4.2.6 and 4.1.9 Reported by: Piotr Widak Issue no.: MDL-69774 CVE identifier: Pending Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
redhat/4.2.6 andto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25979?
The severity of CVE-2024-25979 is classified as minor.
How do I fix CVE-2024-25979?
To fix CVE-2024-25979, you should update your Moodle installation to a version beyond 4.3.3, specifically 4.3.3 or later.
Which versions of Moodle are affected by CVE-2024-25979?
CVE-2024-25979 affects Moodle versions from 4.1.0 up to 4.3.2.
Is CVE-2024-25979 a cross-site scripting vulnerability?
No, CVE-2024-25979 pertains to unrestricted URL parameter acceptance rather than cross-site scripting.
Can CVE-2024-25979 lead to security issues in Moodle?
While CVE-2024-25979 is considered minor, unrestricted URL parameters may potentially lead to unexpected behavior or information leakage.