CVE-2024-25983: Msa-24-0006: idor on dashboard comments block
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
Other sources
MSA-24-0006: IDOR on dashboard comments block
Description: Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (eg on their profile page). Issue summary: IDOR on dashboard comments block Severity/Risk: Minor Versions affected: 4.3 to 4.3.2, 4.2 to 4.2.5, 4.1 to 4.1.8 and earlier unsupported versions Versions fixed: 4.3.3, 4.2.6 and 4.1.9 Reported by: BA7MAN Issue no.: MDL-78300 CVE identifier: Pending Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78300
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
redhat/4.2.6 andto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
moodleto a version that resolves this vulnerability.Fixed in 4.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25983?
CVE-2024-25983 has been classified with a noteworthy severity due to the potential for unauthorized comment manipulation on user dashboards.
How do I fix CVE-2024-25983?
To fix CVE-2024-25983, update Moodle to version 4.1.9, 4.2.6, or 4.3.3 depending on your current version.
What versions of Moodle are affected by CVE-2024-25983?
CVE-2024-25983 affects Moodle versions prior to 4.1.9, versions 4.2.0 to 4.2.6, and versions 4.3.0 to 4.3.3.
What is the impact of CVE-2024-25983?
The impact of CVE-2024-25983 allows unauthorized users to add comments to another user's comments block, potentially leading to privacy violations.
Is there a workaround for CVE-2024-25983?
Currently, the best approach to mitigate CVE-2024-25983 is to apply the available updates since no robust workaround is provided.