Missing Authorization
CVE-2024-48898
Summary
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from. This issue affects moodle/moodle versions 4.0.0-beta through 4.1.13, 4.2.0-beta through 4.2.10, 4.3.0-beta through 4.3.7, 4.4.0-beta through 4.4.3, and 4.5.0-beta through 4.5.0-rc1.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- LOW
- NONE
- NONE
CWE-862 - Missing Authorization
The missing authorization vulnerability occurs when a software program allows users to access privileged parts of the program without verifying the user credentials. Impact of such a vulnerability depends on the resources employed by the software, ranging from account takeover to sensitive information exposure, denial of service, and complete system takeover.
Advisory Timeline
- Published