Description
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
Published: 2024-11-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mg54-p2wj-5ph7 moodle: IDOR when fetching report schedules
History

Wed, 20 Nov 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Weaknesses CWE-863
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle

Mon, 18 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
Title Moodle: idor when fetching report schedules
Weaknesses CWE-285
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-11-18T11:15:18.137Z

Reserved: 2024-10-09T12:15:07.578Z

Link: CVE-2024-48901

cve-icon Vulnrichment

Updated: 2024-11-18T14:56:11.089Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T12:15:18.493

Modified: 2024-11-20T14:45:10.380

Link: CVE-2024-48901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses