๐Ÿ” CVE Alert

CVE-2024-45691

MEDIUM 5.4

Moodle: lesson activity password bypass through php loose comparison

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.

Published Nov 20, 2024
Last Updated Nov 20, 2024
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2309940 moodle.org: https://moodle.org/security/