Accepted
Permalink
CVE-2024-48898
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
by @fricklerhandwerk Activity log
- Created automatic suggestion
- @fricklerhandwerk accepted
Moodle: some users can delete audiences of other reports
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
References
Affected products
moodle
- <4.2.11
- <4.1.0
- <4.3.8
- <4.4.4
- <4.1.14
Package maintainers
-
@freezeboy freezeboy