CVE-2024-48901: Moodle: idor when fetching report schedules
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
Other sources
Additional checks were required to ensure users can only access the schedule of a report if they have permission to edit that report.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48901?
CVE-2024-48901 has a medium severity rating due to potential unauthorized access to report schedules in Moodle.
How do I fix CVE-2024-48901?
To resolve CVE-2024-48901, upgrade Moodle to versions 4.4.5, 4.3.9, 4.2.12, or 4.1.15, which include the necessary permission checks.
What versions of Moodle are affected by CVE-2024-48901?
CVE-2024-48901 affects Moodle versions up to 4.4.4, 4.3.8, 4.2.11, and 4.1.14.
Is CVE-2024-48901 exploit-related?
CVE-2024-48901 can lead to unauthorized schedule access if left unpatched, representing a potential exploit vector.
Where can I find more information about CVE-2024-48901?
Detailed information on CVE-2024-48901 can be found in security advisories and vulnerability databases.