vulnerability
Moodle: Improper Access Control (CVE-2024-25980)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | Feb 19, 2024 | Jan 27, 2025 | May 7, 2026 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Feb 19, 2024
Added
Jan 27, 2025
Modified
May 7, 2026
Description
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
Solution
moodle-upgrade-latest
References
- CVE-2024-25980
- https://attackerkb.com/topics/CVE-2024-25980
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80501
- https://bugzilla.redhat.com/show_bug.cgi?id=2264096
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/
- https://moodle.org/mod/forum/discuss.php?d=455636
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0619
- CWE-284
- EUVD-EUVD-2024-0619
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.