CVE-2024-45689
- EPSS 0.09%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:33:57
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
CVE-2024-45690
- EPSS 0.39%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:34:48
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
CVE-2024-45691
- EPSS 0.29%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:35:23
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic ha...
CVE-2024-48899
- EPSS 0.14%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:36:03
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
CVE-2024-48896
- EPSS 0.23%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:47:12
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name fo...
CVE-2024-48897
- EPSS 0.23%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:48:25
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
CVE-2024-48898
- EPSS 0.23%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:46:16
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
CVE-2024-48901
- EPSS 0.23%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:45:10
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
CVE-2024-48900
- EPSS 0.2%
- Veröffentlicht 13.11.2024 15:15:07
- Zuletzt bearbeitet 13.06.2025 00:33:54
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
CVE-2024-43439
- EPSS 0.96%
- Veröffentlicht 11.11.2024 16:15:14
- Zuletzt bearbeitet 23.04.2025 21:26:17
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.