CVE-2024-45689: Moodle

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

Affected products

  • Moodle Moodle: before 4.1.13 (fixed in 4.1.13); from 4.2.0, before 4.2.10 (fixed in 4.2.10); from 4.3.0, before 4.3.7 (fixed in 4.3.7); from 4.4.0, before 4.4.3 (fixed in 4.4.3)

Published 2024-11-20. Last modified 2026-06-17.