CVE-2024-43429: Moodle

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

Affected products

  • Moodle Moodle: before 4.1.12 (fixed in 4.1.12); from 4.2.0, before 4.2.9 (fixed in 4.2.9); from 4.3.0, before 4.3.6 (fixed in 4.3.6); from 4.4.0, before 4.4.2 (fixed in 4.4.2)

Published 2024-11-11. Last modified 2026-06-17.