5.3
CVE-2024-43430
- EPSS 0.43%
- Veröffentlicht 11.11.2024 13:15:04
- Zuletzt bearbeitet 01.05.2025 16:08:09
- Quelle patrick@puiterwijk.org
- CVE-Watchlists
- Unerledigt
Moodle: lack of access control when using external methods for quiz overrides
Lack of access control when using external methods for Quiz overrides
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
Mögliche Gegenmaßnahme
Moodle Server: Update to a patched version.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.62 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| patrick@puiterwijk.org | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.