First published: Tue Oct 15 2024(Updated: )
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=4.4.0<4.4.4 | 4.4.4 |
composer/moodle/moodle | >=4.3.0<4.3.8 | 4.3.8 |
composer/moodle/moodle | >=4.2.0<4.2.11 | 4.2.11 |
composer/moodle/moodle | <4.1.14 | 4.1.14 |
Moodle | <=4.1.14 | |
Moodle | >=4.2.0<=4.2.11 | |
Moodle | >=4.3.0<=4.3.8 | |
Moodle | >=4.4.0<=4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48897 is a vulnerability in Moodle that requires additional checks to ensure users can only edit or delete RSS feeds they have permission to modify.
CVE-2024-48897 affects Moodle versions from 4.1.14 up to but not including 4.4.4, along with versions 4.2.0 to 4.2.11 and 4.3.0 to 4.3.8.
The severity of CVE-2024-48897 can potentially lead to unauthorized editing or deletion of RSS feeds, depending on user permissions.
To fix CVE-2024-48897, update your Moodle installation to version 4.4.4, 4.3.8, or 4.2.11.
CVE-2024-48897 may allow unauthorized users to modify or delete RSS feeds that they should not have access to.