PT-2024-8619 · Moodle+2 · Moodle+2

Stefan Wilhelm

·

Published

2024-08-19

·

Updated

2025-05-02

·

CVE-2024-43429

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw in Moodle allows hidden user profile fields to be visible in gradebook reports. This could result in users without the view hidden user fields capability having access to confidential information. The issue is related to the storage of critical information in an open manner, which can be exploited by a remote attacker to gain access to sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16385
ALT-PU-2024-16417
BDU:2024-10193
BIT-MOODLE-2024-43429
CVE-2024-43429
GHSA-C767-4WHH-V7RW

Affected Products

Alt Linux
Moodle
Red Os