Accepted
Permalink
CVE-2024-45689
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
Moodle: unprotected access to sensitive information via dynamic tables
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
References
Affected products
moodle
- <4.3.7
- <4.2.10
- <4.1.13
- <4.4.3
Package maintainers
-
@freezeboy freezeboy