CVE-2024-25983

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/02/2024
Last modified:
23/01/2025

Description

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.1.0 (including) 4.1.9 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.6 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.3.0 (including) 4.3.3 (excluding)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*