CVE-2024-43440: Moodle: lfi vulnerability when restoring malformed block backups
Published Nov 7, 2024
·Updated
A flaw was found in moodle. A local file may include risks when restoring block backups.
Affected Software
8 affected componentsFixes available
composer/moodle/moodle>=4.4.0-beta<4.4.2
4.4.2
composer/moodle/moodle>=4.3.0-beta<4.3.6
4.3.6
composer/moodle/moodle>=4.2.0-beta<4.2.9
4.2.9
composer/moodle/moodle<4.1.12
4.1.12
Moodle moodle<4.1.12
Moodle moodle>=4.2.0<4.2.9
Moodle moodle>=4.3.0<4.3.6
Moodle moodle>=4.4.0<4.4.2
Event History
Nov 7, 2024
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-43440?
CVE-2024-43440 is considered a high severity vulnerability due to the risks involved in restoring block backups.
2
Who is affected by CVE-2024-43440?
CVE-2024-43440 affects Moodle versions 4.4.0-beta to 4.4.2, 4.3.0-beta to 4.3.6, 4.2.0-beta to 4.2.9, and all versions up to 4.1.12.
3
How do I fix CVE-2024-43440?
To fix CVE-2024-43440, update Moodle to the latest versions 4.4.2, 4.3.6, 4.2.9, or 4.1.12.
4
What impact does CVE-2024-43440 have on Moodle?
CVE-2024-43440 may allow local file inclusion vulnerabilities when restoring block backups in Moodle.
5
Can CVE-2024-43440 be exploited remotely?
CVE-2024-43440 is primarily a local vulnerability and cannot be exploited remotely.