CVE-2024-48898: Moodle

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

Affected products

  • Moodle Moodle: up to and including 4.1.14; from 4.2.0, up to and including 4.2.11; from 4.3.0, up to and including 4.3.8; from 4.4.0, up to and including 4.4.4

Published 2024-11-18. Last modified 2026-06-17.