First published: Mon Nov 11 2024(Updated: )
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=4.4.0<4.4.2 | 4.4.2 |
Moodle | >=4.4.0<4.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43430 has a medium severity rating due to insufficient access control vulnerabilities.
To fix CVE-2024-43430, upgrade your Moodle installation to version 4.4.2 or later.
CVE-2024-43430 affects Moodle versions from 4.4.0 to 4.4.2.
CVE-2024-43430 allows unauthorized external API access, potentially compromising user data.
Currently, there are no recommended workarounds for CVE-2024-43430 other than upgrading.