First published: Mon Nov 11 2024(Updated: )
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <4.1.12 | 4.1.12 |
composer/moodle/moodle | >=4.2.0<4.2.9 | 4.2.9 |
composer/moodle/moodle | >=4.3.0<4.3.6 | 4.3.6 |
composer/moodle/moodle | >=4.4.0<4.4.2 | 4.4.2 |
Moodle | <4.1.12 | |
Moodle | >=4.2.0<4.2.9 | |
Moodle | >=4.3.0<4.3.6 | |
Moodle | >=4.4.0<4.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43429 has been classified as a medium severity vulnerability due to unauthorized access to hidden user profile fields.
To fix CVE-2024-43429, upgrade to Moodle versions 4.1.12, 4.2.9, 4.3.6, or 4.4.2 or later.
Users of Moodle versions prior to 4.1.12, 4.2.9, 4.3.6, and 4.4.2 are potentially affected by CVE-2024-43429.
CVE-2024-43429 exposes hidden user profile fields in gradebook reports, allowing unauthorized access to sensitive information.
Yes, CVE-2024-43429 is related to user permissions as it involves users without the 'view hidden user fields' capability gaining access to restricted information.