vulnerability
Moodle: Authorization Bypass Through User-Controlled Key (CVE-2024-48899)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | Nov 20, 2024 | Jun 4, 2025 | Jul 28, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Nov 20, 2024
Added
Jun 4, 2025
Modified
Jul 28, 2025
Description
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
Solution
moodle-upgrade-4_4_4
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.