A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2318819 |
![]() ![]() |
History
Mon, 02 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Moodle
Moodle moodle |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
Vendors & Products |
Moodle
Moodle moodle |
Wed, 20 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 20 Nov 2024 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to. | |
Title | Moodle: idor when accessing list of course badges | |
Weaknesses | CWE-284 | |
References |
|

Status: PUBLISHED
Assigner: fedora
Published: 2024-11-20T10:25:58.315Z
Updated: 2024-11-20T19:16:12.331Z
Reserved: 2024-10-09T12:15:07.577Z
Link: CVE-2024-48899

Updated: 2024-11-20T19:16:03.038Z

Status : Analyzed
Published: 2024-11-20T11:15:05.563
Modified: 2025-06-02T15:36:03.710
Link: CVE-2024-48899

No data.