Information disclosure in Moodle - CVE-2024-55645

 

Information disclosure in Moodle - CVE-2024-55645

Published: December 17, 2024


Vulnerability identifier: #VU101808
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55645
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to the email change confirmation token is available via preference. A remote user or attacker with physical access to the system can obtain the token and use it later to verify the email change without having access to the mailbox.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2024-55645

Install updates from vendor's website.

Moodle - addressed in versions 4.1.15, 4.3.9, 4.4.5, 4.5.1
moodle - addressed in versions 4.3.9-1.fc40, 4.4.5-1.fc41

External References

Related Security Bulletins