Vulnerability Database
Blog
FAQ
Docs
CVE-2024-25979
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-25979
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25979.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-25979
Aliases
BIT-moodle-2024-25979
GHSA-6vjf-48fh-vxxj
Related
UBUNTU-CVE-2024-25979
Published
2024-02-19T17:15:08Z
Modified
2025-01-24T02:00:49.650571Z
Severity
5.3 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Calculator
Summary
[none]
Details
The URL parameters accepted by forum search were not limited to the allowed parameters.
References
https://moodle.org/mod/forum/discuss.php?d=455635
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXGBYJ43BUEBUAQZU3DT5I5A3YLF47CB/
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
https://bugzilla.redhat.com/show_bug.cgi?id=2264095
Affected packages
Git
/
github.com/moodle/moodle
Affected ranges
Type
GIT
Repo
https://github.com/moodle/moodle
Events
Introduced
0ea3d45e04c3d54a3a472ddcb11606b30e227c50
Fixed
8a38a37f1ff5075c6f46d726c1457172c2fccac3
Affected versions
v4.*
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
CVE-2024-25979 - OSV