CVE-2024-48899

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 284

Summary

CVE-2024-48899 is a newly identified vulnerability affecting the Moodle learning management system. This issue permits unintended users to access the list of course badges for courses they should not have access to, due to insufficient access checks. This could potentially lead to unauthorized disclosure of sensitive information or confusion among users. It is crucial for Moodle administrators to apply the necessary patches or updates as soon as possible to mitigate this vulnerability and maintain the security of their learning environments.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share