CVE-2024-33999: moodle: unsafe direct use of $_SERVER['HTTP_REFERER'] in admin/tool/mfa/index.php
Published May 31, 2024
·Updated
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
Affected Software
2 affected componentsFixes available
composer/moodle/moodle>=4.3.0<4.3.4
4.3.4
Moodle moodle>=4.3.0<4.3.4
Event History
May 31, 2024
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
SeverityAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33999?
CVE-2024-33999 has not been assigned a specific CVSS score yet but represents a critical vulnerability due to unsafe handling of user input.
2
How do I fix CVE-2024-33999?
To fix CVE-2024-33999, upgrade to Moodle version 4.3.4 or later, where the vulnerability has been addressed.
3
What affected software versions are impacted by CVE-2024-33999?
CVE-2024-33999 affects Moodle versions from 4.3.0 to 4.3.3.
4
What type of vulnerability is CVE-2024-33999?
CVE-2024-33999 is a vulnerability related to improper input validation in the HTTP referer handling.
5
What potential impact does CVE-2024-33999 have on users?
CVE-2024-33999 may allow an attacker to exploit the vulnerability to execute malicious actions as an administrator.