CVE-2024-25980
published 2024-02-19CVE-2024-25980: Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.53%
41.4th percentile
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| moodle | moodle | >= 0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.1.0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Access Control in moodle
osv·2024-02-19
CVE-2024-25980 [MEDIUM] Improper Access Control in moodle
Improper Access Control in moodle
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
OSV
CVE-2024-25980: Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups
osv·2024-02-19·CVSS 5.3
CVE-2024-25980 [MEDIUM] CVE-2024-25980: Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
GHSA
Improper Access Control in moodle
ghsa·2024-02-19
CVE-2024-25980 [MEDIUM] CWE-284 Improper Access Control in moodle
Improper Access Control in moodle
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80501https://bugzilla.redhat.com/show_bug.cgi?id=2264096https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455636http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80501https://bugzilla.redhat.com/show_bug.cgi?id=2264096https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455636
2024-02-19
Published