CVE-2024-25979
published 2024-02-19CVE-2024-25979: The URL parameters accepted by forum search were not limited to the allowed parameters.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.59%
44.1th percentile
The URL parameters accepted by forum search were not limited to the allowed parameters.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| moodle | moodle | >= 0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.1.0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Handling of Parameters in moodle
osv·2024-02-19
CVE-2024-25979 [MEDIUM] Improper Handling of Parameters in moodle
Improper Handling of Parameters in moodle
The URL parameters accepted by forum search were not limited to the allowed parameters.
GHSA
Improper Handling of Parameters in moodle
ghsa·2024-02-19
CVE-2024-25979 [MEDIUM] CWE-233 Improper Handling of Parameters in moodle
Improper Handling of Parameters in moodle
The URL parameters accepted by forum search were not limited to the allowed parameters.
OSV
CVE-2024-25979: The URL parameters accepted by forum search were not limited to the allowed parameters
osv·2024-02-19·CVSS 5.3
CVE-2024-25979 [MEDIUM] CVE-2024-25979: The URL parameters accepted by forum search were not limited to the allowed parameters
The URL parameters accepted by forum search were not limited to the allowed parameters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774https://bugzilla.redhat.com/show_bug.cgi?id=2264095https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455635http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774https://bugzilla.redhat.com/show_bug.cgi?id=2264095https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455635
2024-02-19
Published