CVE-2024-48899: Moodle

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

Affected products

  • Moodle Moodle: from 4.4.0, before 4.4.4 (fixed in 4.4.4)

Published 2024-11-20. Last modified 2026-06-17.