CVE-2024-43430: Moodle: lack of access control when using external methods for quiz overrides
Published Nov 11, 2024
·Updated
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
Affected Software
2 affected componentsFixes available
composer/moodle/moodle>=4.4.0<4.4.2
4.4.2
Moodle moodle>=4.4.0<4.4.2
Event History
Nov 11, 2024
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-43430?
CVE-2024-43430 has a medium severity rating due to insufficient access control vulnerabilities.
2
How do I fix CVE-2024-43430?
To fix CVE-2024-43430, upgrade your Moodle installation to version 4.4.2 or later.
3
Which versions of Moodle are affected by CVE-2024-43430?
CVE-2024-43430 affects Moodle versions from 4.4.0 to 4.4.2.
4
What is the impact of CVE-2024-43430 on Moodle users?
CVE-2024-43430 allows unauthorized external API access, potentially compromising user data.
5
Is there a workaround for CVE-2024-43430 before upgrading?
Currently, there are no recommended workarounds for CVE-2024-43430 other than upgrading.