Skip to main content

Incorrect Default Permissions

CVE-2024-45690

Severity Medium
Score 5.3/10

Summary

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. This issue affects moodle/moodle versions 3.3.0-beta through 4.1.12, 4.2.0-beta through 4.2.9, 4.3.0-beta through 4.3.6, and 4.4.0-beta through 4.4.2.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-276 - Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

Advisory Timeline

  • Published