PT-2024-8805 · Moodle+2 · Moodle+2
CVE-2024-45689
·
Published
2024-09-04
·
Updated
2025-06-03
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Moodle (affected versions not specified)
Description:
A flaw was found in the dynamic tables of Moodle, where capability checks were not enforced, allowing users to retrieve information they did not have permission to access. This issue is related to insufficient access control in the core table/dynamic module of the virtual learning environment. The exploitation of this flaw can enable a remote attacker to gain unauthorized access to protected information.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Improper Privilege Management
Improper Authorization
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Moodle
Red Os