CVE-2024-48899: Moodle: idor when accessing list of course badges
Published Oct 15, 2024
·Updated
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Other sources
Additional checks were required to ensure users can only fetch the list of course badges for courses they are intended to have access to.
— Red Hat
Affected Software
2 affected componentsFixes available
composer/moodle/moodle>=4.4.0-beta<4.4.3
4.4.3
Moodle moodle>=4.4.0<4.4.4
Event History
Oct 15, 2024
Data Sourced
via Red Hat·05:32 PM
DescriptionSeverityAffected Software
Nov 20, 2024
CVE Published
via MITRE·10:25 AM
Data Sourced
via MITRE·10:25 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
Severity
Advisory Published
via GitHub·12:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-48899?
CVE-2024-48899 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-48899?
To fix CVE-2024-48899, upgrade to Moodle version 4.4.4 or later.
3
Who is affected by CVE-2024-48899?
CVE-2024-48899 affects users of Moodle versions between 4.4.0-beta and 4.4.3.
4
What type of vulnerability is CVE-2024-48899?
CVE-2024-48899 is an access control vulnerability related to course badge visibility.
5
Can CVE-2024-48899 lead to data exposure?
Yes, CVE-2024-48899 could potentially allow unauthorized users to fetch course badges they should not access.