CVE-2024-43429

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 312

Summary

CVE-2024-43429 is a vulnerability affecting Moodle, an open-source learning management system. This issue arises from hidden user profile fields being accessible in gradebook reports. Users who lack the "view hidden user fields" capability may still gain unauthorized access to this sensitive information, potentially leading to privacy breaches. This vulnerability could pose a significant risk to institutions using Moodle for online education, and it is recommended that affected organizations apply the necessary patches as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share