CVE-2024-45689

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

02 Jun 2025, 15:33

Type Values Removed Values Added
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
First Time Moodle moodle
Moodle
References () https://bugzilla.redhat.com/show_bug.cgi?id=2309941 - () https://bugzilla.redhat.com/show_bug.cgi?id=2309941 - Issue Tracking
CWE CWE-862

20 Nov 2024, 20:35

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Moodle. Las tablas dinámicas no aplicaban comprobaciones de capacidad, lo que provocaba que los usuarios pudieran recuperar información a la que no tenían permiso de acceso.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Nov 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-20 11:15

Updated : 2025-06-02 15:33


NVD link : CVE-2024-45689

Mitre link : CVE-2024-45689

CVE.ORG link : CVE-2024-45689


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-862

Missing Authorization