vulnerability

Moodle: Authorization Bypass Through User-Controlled Key (CVE-2024-48899)

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Nov 20, 2024
Added
Jun 4, 2025
Modified
Jul 28, 2025

Description

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

Solution

moodle-upgrade-4_4_4
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.