Information disclosure in Moodle - CVE-2024-55645
Published: December 17, 2024
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to the email change confirmation token is available via preference. A remote user or attacker with physical access to the system can obtain the token and use it later to verify the email change without having access to the mailbox.
Affected software
Fedora
moodle
How to mitigate CVE-2024-55645
moodle - addressed in versions 4.3.9-1.fc40, 4.4.5-1.fc41