First published: Tue Feb 13 2024(Updated: )
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/moodle | <4.3.3 | 4.3.3 |
redhat/4.2.6 and | <4.1.9 | 4.1.9 |
composer/moodle/moodle | <4.1.9 | 4.1.9 |
composer/moodle/moodle | >=4.2.0<4.2.6 | 4.2.6 |
composer/moodle/moodle | >=4.3.0<4.3.3 | 4.3.3 |
Moodle | >=4.1.0<4.1.9 | |
Moodle | >=4.2.0<4.2.6 | |
Moodle | >=4.3.0<4.3.3 | |
Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25983 has been classified with a noteworthy severity due to the potential for unauthorized comment manipulation on user dashboards.
To fix CVE-2024-25983, update Moodle to version 4.1.9, 4.2.6, or 4.3.3 depending on your current version.
CVE-2024-25983 affects Moodle versions prior to 4.1.9, versions 4.2.0 to 4.2.6, and versions 4.3.0 to 4.3.3.
The impact of CVE-2024-25983 allows unauthorized users to add comments to another user's comments block, potentially leading to privacy violations.
Currently, the best approach to mitigate CVE-2024-25983 is to apply the available updates since no robust workaround is provided.