CVE-2024-25983: Msa-24-0006: idor on dashboard comments block

Published Feb 13, 2024
·
Updated

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

Other sources

MSA-24-0006: IDOR on dashboard comments block

Description: Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (eg on their profile page). Issue summary: IDOR on dashboard comments block Severity/Risk: Minor Versions affected: 4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versions Versions fixed: 4.3.3, 4.2.6 and 4.1.9 Reported by: BA7MAN Issue no.: MDL-78300 CVE identifier: Pending Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78300

Red Hat

Affected Software

9 affected componentsFixes available
redhat/moodle<4.3.3
4.3.3
redhat/4.2.6 and<4.1.9
4.1.9
composer/moodle/moodle<4.1.9
4.1.9
composer/moodle/moodle>=4.2.0<4.2.6
4.2.6
composer/moodle/moodle>=4.3.0<4.3.3
4.3.3
Moodle moodle>=4.1.0<4.1.9
Moodle moodle>=4.2.0<4.2.6
Moodle moodle>=4.3.0<4.3.3
Fedoraproject Fedora=38

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/moodle/moodle to a version that resolves this vulnerability.

    Fixed in 4.1.9
  2. Upgrade

    Upgrade composer/moodle/moodle to a version that resolves this vulnerability.

    Fixed in 4.2.6
  3. Upgrade

    Upgrade composer/moodle/moodle to a version that resolves this vulnerability.

    Fixed in 4.3.3
  4. Upgrade

    Upgrade redhat/moodle to a version that resolves this vulnerability.

    Fixed in 4.3.3
  5. Upgrade

    Upgrade redhat/4.2.6 and to a version that resolves this vulnerability.

    Fixed in 4.1.9
  6. Upgrade

    Upgrade moodle to a version that resolves this vulnerability.

    Fixed in 4.3.3
  7. Upgrade

    Upgrade moodle to a version that resolves this vulnerability.

    Fixed in 4.2.6
  8. Upgrade

    Upgrade moodle to a version that resolves this vulnerability.

    Fixed in 4.1.9

Event History

Feb 13, 2024
Data Sourced
via Red Hat·09:39 PM
DescriptionSeverityAffected Software
Feb 19, 2024
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-25983?

CVE-2024-25983 has been classified with a noteworthy severity due to the potential for unauthorized comment manipulation on user dashboards.

2

How do I fix CVE-2024-25983?

To fix CVE-2024-25983, update Moodle to version 4.1.9, 4.2.6, or 4.3.3 depending on your current version.

3

What versions of Moodle are affected by CVE-2024-25983?

CVE-2024-25983 affects Moodle versions prior to 4.1.9, versions 4.2.0 to 4.2.6, and versions 4.3.0 to 4.3.3.

4

What is the impact of CVE-2024-25983?

The impact of CVE-2024-25983 allows unauthorized users to add comments to another user's comments block, potentially leading to privacy violations.

5

Is there a workaround for CVE-2024-25983?

Currently, the best approach to mitigate CVE-2024-25983 is to apply the available updates since no robust workaround is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203