Skip to main content

Missing Authorization

CVE-2024-43431

Severity High
Score 7.5/10

Summary

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access. This issue affects moodle/moodle versions 2.5.0-beta through 4.1.11, 4.2.0-beta through 4.2.8, 4.3.0-beta through 4.3.5, and 4.4.0-beta through 4.4.1.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-862 - Missing Authorization

The missing authorization vulnerability occurs when a software program allows users to access privileged parts of the program without verifying the user credentials. Impact of such a vulnerability depends on the resources employed by the software, ranging from account takeover to sensitive information exposure, denial of service, and complete system takeover.

Advisory Timeline

  • Published