Skip to main content

Improper Handling of Parameters

CVE-2024-25979

Severity Medium
Score 5.3/10

Summary

The "URL" parameters accepted by forum search were not limited to the allowed parameters. This issue affects moodle/moodle versions prior to 4.1.9, 4.2.x prior to 4.2.6, and 4.3.x prior to 4.3.3.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-233 - Improper Handling of Parameters

The software does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.

Advisory Timeline

  • Published