PT-2024-21255 · Moodle+1 · Moodle+1

Leon Stringer

·

Published

2024-02-19

·

Updated

2024-06-19

·

CVE-2024-25980

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The issue concerns the H5P attempts report in Separate Groups mode, where restrictions were not properly enforced, allowing the display of users from other groups. By default, this provided additional access to non-editing teachers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-8851
ALT-PU-2024-9067
BIT-MOODLE-2024-25980
CVE-2024-25980
GHSA-CP8M-H777-G4P3

Affected Products

Alt Linux
Moodle