CVE-2024-48899
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 284
Summary
CVE-2024-48899 is a newly identified vulnerability affecting the Moodle learning management system. This issue permits unintended users to access the list of course badges for courses they should not have access to, due to insufficient access checks. This could potentially lead to unauthorized disclosure of sensitive information or confusion among users. It is crucial for Moodle administrators to apply the necessary patches or updates as soon as possible to mitigate this vulnerability and maintain the security of their learning environments.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share