← back
CVE-2024-48900

Moodle: idor when accessing list of badge recipients

CVSS 4.3 MEDIUMEPSS 0.3%CWE-200
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →