CVE-2024-48899

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
20/11/2024
Last modified:
02/06/2025

Description

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.4.0 (including) 4.4.4 (excluding)


References to Advisories, Solutions, and Tools