CVE-2024-48898: Moodle: some users can delete audiences of other reports
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
Other sources
Users with access to delete audiences from some reports could delete audiences from other reports they did not have permission to delete from.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48898?
CVE-2024-48898 has been categorized as a moderate severity vulnerability.
How do I fix CVE-2024-48898?
To fix CVE-2024-48898, upgrade your Moodle installation to version 4.4.4, 4.3.8, or 4.2.11 as applicable.
Who is affected by CVE-2024-48898?
CVE-2024-48898 affects users of Moodle versions up to and including 4.4.4, 4.3.8, and 4.2.11.
What type of vulnerability is CVE-2024-48898?
CVE-2024-48898 is a permissions vulnerability that allows unauthorized deletion of audiences from reports.
What impact does CVE-2024-48898 have on users?
CVE-2024-48898 can potentially allow users to delete important report data that they should not have access to.