PT-2024-9765 · Moodle+2 · Moodle+2

Marina Glancy

·

Published

2024-08-07

·

Updated

2025-05-02

·

CVE-2024-43432

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Moodle (affected versions not specified)
Description: A flaw was found in the cURL wrapper in Moodle, which strips HTTPAUTH and USERPWD headers during emulated redirects but retains other original request headers. This could lead to HTTP authorization header information being unintentionally sent in requests to redirect URLs, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16385
ALT-PU-2024-16417
BDU:2024-11511
BIT-MOODLE-2024-43432
CVE-2024-43432
GHSA-7WMP-2XMX-G6H8

Affected Products

Alt Linux
Moodle
Red Os