CVE-2024-43429: Moodle: user information visibility control issues in gradebook reports
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43429?
CVE-2024-43429 has been classified as a medium severity vulnerability due to unauthorized access to hidden user profile fields.
How do I fix CVE-2024-43429?
To fix CVE-2024-43429, upgrade to Moodle versions 4.1.12, 4.2.9, 4.3.6, or 4.4.2 or later.
Who is affected by CVE-2024-43429?
Users of Moodle versions prior to 4.1.12, 4.2.9, 4.3.6, and 4.4.2 are potentially affected by CVE-2024-43429.
What does CVE-2024-43429 expose?
CVE-2024-43429 exposes hidden user profile fields in gradebook reports, allowing unauthorized access to sensitive information.
Is CVE-2024-43429 related to user permissions?
Yes, CVE-2024-43429 is related to user permissions as it involves users without the 'view hidden user fields' capability gaining access to restricted information.