5.3

CVE-2024-43430

Moodle: lack of access control when using external methods for quiz overrides

Lack of access control when using external methods for Quiz overrides

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
Mögliche Gegenmaßnahme
Moodle Server: Update to a patched version.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 4.4.0 < 4.4.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemMoodle
≫
Produkt Moodle Server
Version >= 4.4.0, < 4.4.2
Version >= 4.4.1, <= 4.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.255
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
patrick@puiterwijk.org 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://bugzilla.redhat.com/show_bug.cgi?id=2304258
Permissions Required
https://moodle.org/mod/forum/discuss.php?d=461198
Vendor Advisory
https://moodle.org/mod/forum/discuss.php?d=461198
Third Party Advisory