CVE-2024-48900: Moodle: idor when accessing list of badge recipients
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
Other sources
Additional checks were required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48900?
CVE-2024-48900 has been classified as a moderate severity vulnerability due to the potential for unauthorized access to badge recipient lists.
How do I fix CVE-2024-48900?
To fix CVE-2024-48900, update your Moodle version to ensure that proper access controls are implemented for viewing badge recipients.
Who is affected by CVE-2024-48900?
CVE-2024-48900 affects users of Moodle version 4.4.0 to 4.4.4 who have permission to view badge recipients.
What type of vulnerability is CVE-2024-48900?
CVE-2024-48900 represents an access control issue that fails to adequately restrict user permissions for viewing badge recipient lists.
When was CVE-2024-48900 disclosed?
CVE-2024-48900 was disclosed as part of an ongoing security assessment of the Moodle platform, with specific details released in the last quarter of 2023.