PT-2024-8664 · Moodle+2 · Moodle+2

Published

2024-10-14

·

Updated

2024-12-03

·

CVE-2024-48897

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A vulnerability was found in Moodle, related to insufficient authentication procedure, which may allow a remote attacker to gain unauthorized access to system elements. The issue requires additional checks to ensure users can only edit or delete RSS feeds that they have permission to modify.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16385
ALT-PU-2024-16417
BDU:2024-10263
BIT-MOODLE-2024-48897
CVE-2024-48897
GHSA-X3X9-349X-2485

Affected Products

Alt Linux
Moodle
Red Os