CVE-2024-48899
- EPSS 0.17%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:36:03
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
CVE-2024-48896
- EPSS 0.24%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:47:12
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name fo...
CVE-2024-48897
- EPSS 0.2%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:48:25
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
CVE-2024-48898
- EPSS 0.2%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:46:16
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
CVE-2024-48901
- EPSS 0.2%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:45:10
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
CVE-2024-48900
- EPSS 0.21%
- Veröffentlicht 13.11.2024 15:15:07
- Zuletzt bearbeitet 13.06.2025 00:33:54
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
CVE-2024-43439
- EPSS 0.65%
- Veröffentlicht 11.11.2024 16:15:14
- Zuletzt bearbeitet 23.04.2025 21:26:17
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
CVE-2024-43430
- EPSS 0.41%
- Veröffentlicht 11.11.2024 13:15:04
- Zuletzt bearbeitet 01.05.2025 16:08:09
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
CVE-2024-43432
- EPSS 0.21%
- Veröffentlicht 11.11.2024 13:15:04
- Zuletzt bearbeitet 01.05.2025 16:08:59
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to re...
CVE-2024-43433
- EPSS 0.41%
- Veröffentlicht 11.11.2024 13:15:04
- Zuletzt bearbeitet 01.05.2025 16:09:18
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.