CyberzSOC

Publication detail
← Back to advisories & guidance

2024-085: Multiple Vulnerabilities in Moodle ↗ source

August 21, 2024 CERT-EU Advisory

Summary

Several CVEs have been assigned with a Serious severity or risk by Moodle. The vulnerability CVE-2024-43440 is a Local File Inclusion (LFI) flaw triggered when restoring The vulnerability CVE-2024-43439 is a flaw in unsanitised H5P error messages allowing for Reflected Cross-Site Scripting (XSS) [4]. The vulnerability CVE-2024-43436 is an SQL injection flaw in the XMLDB editor tool available The vulnerability CVE-2024-43434 is a flaw in the bulk message sending feature for the feedback module’s non-respondents report due to an incorrect CSRF token check, and possibly leading to Cross-Site Request Forgery (CSRF) [6]. The vulnerability CVE-2024-43431 is an Insecure Direct Object Reference (IDOR) flaw that allows users to delete badges they do not have permission to access due to insufficient capability The vulnerability CVE-2024-43428 is a cache poisoning flaw due to insufficient validation of local storage, allowing injection into the storage mechanism [8]. The vulnerability CVE-2024-43426 is a serious arbitrary file read flaw due to insufficient sanitisation in the TeX notation filter, affecting sites where pdfTeX is available [9].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-43425 8.1 High — A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi…
CVE-2024-43434 8.1 High — The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil…
CVE-2024-43428 7.7 High — To address a cache poisoning risk in Moodle, additional validation for local storage was required.
CVE-2024-43426 7.5 High — A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is avail…
CVE-2024-43431 7.5 High — A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
CVE-2024-43440 7.5 High — A flaw was found in moodle. A local file may include risks when restoring block backups.
CVE-2024-43436 7.2 High — A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
CVE-2024-43439 5.4 Medium — A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.