Missing Authorization
CVE-2024-43431
Summary
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access. This issue affects moodle/moodle versions 2.5.0-beta through 4.1.11, 4.2.0-beta through 4.2.8, 4.3.0-beta through 4.3.5, and 4.4.0-beta through 4.4.1.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-862 - Missing Authorization
The missing authorization vulnerability occurs when a software program allows users to access privileged parts of the program without verifying the user credentials. Impact of such a vulnerability depends on the resources employed by the software, ranging from account takeover to sensitive information exposure, denial of service, and complete system takeover.
Advisory Timeline
- Published