CVE-2024-25983
published 2024-02-19CVE-2024-25983: Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.60%
44.8th percentile
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| moodle | moodle | >= 0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.1.0 < 4.1.9 | 4.1.9 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.2.0 < 4.2.6 | 4.2.6 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
| moodle | moodle | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authorization Bypass in moodle
osv·2024-02-19
CVE-2024-25983 [MEDIUM] Authorization Bypass in moodle
Authorization Bypass in moodle
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
OSV
CVE-2024-25983: Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise avai
osv·2024-02-19·CVSS 5.3
CVE-2024-25983 [MEDIUM] CVE-2024-25983: Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise avai
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
GHSA
Authorization Bypass in moodle
ghsa·2024-02-19
CVE-2024-25983 [MEDIUM] CWE-639 Authorization Bypass in moodle
Authorization Bypass in moodle
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78300https://bugzilla.redhat.com/show_bug.cgi?id=2264099https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455641http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-78300https://bugzilla.redhat.com/show_bug.cgi?id=2264099https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/https://moodle.org/mod/forum/discuss.php?d=455641
2024-02-19
Published