Accepted
Permalink
CVE-2024-48897
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
Moodle: idor in edit/delete rss feed
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
References
Affected products
moodle
- <4.3.8
- <4.4.4
- <4.2.11
- <4.1.0
- <4.1.14
Package maintainers
-
@freezeboy freezeboy