CVE-2024-43426: Moodle

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

Affected products

  • Moodle Moodle: from 4.1.0, before 4.1.12 (fixed in 4.1.12); from 4.2.0, before 4.2.9 (fixed in 4.2.9); from 4.3.0, before 4.3.6 (fixed in 4.3.6); from 4.4.0, before 4.4.2 (fixed in 4.4.2)

Published 2024-11-07. Last modified 2026-06-17.