CVE-2024-43427

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 922

Summary

CVE-2024-43427 is a newly discovered vulnerability in Moodle, an open-source learning platform. This issue arises when generating an export of site administration presets. Sensitive secrets and keys are inadvertently included in the export, increasing the risk of unintended disclosure if these presets are shared with external parties. This vulnerability could potentially expose sensitive information, making it crucial for Moodle administrators to exercise caution when handling and sharing site administration presets. It is recommended that users update their Moodle installations to the latest version, which is expected to address this vulnerability, to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share