CVE-2024-25980Improper Access Control in Moodle

Severity
5.3MEDIUMNVD
CNA4.3
EPSS
0.2%
top 62.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19

Description

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDmoodle/moodle4.1.04.1.9+2
Packagistmoodle/moodle4.3.04.3.3+2

Also affects: Fedora 38

Patches

🔴Vulnerability Details

4
OSV
Improper Access Control in moodle2024-02-19
CVEList
Msa-24-0003: h5p attempts report did not respect activity group settings2024-02-19
OSV
CVE-2024-25980: Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups2024-02-19
GHSA
Improper Access Control in moodle2024-02-19
CVE-2024-25980 — Improper Access Control in Moodle | cvebase