CVE-2024-48901: Moodle

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

Affected products

  • Moodle Moodle: up to and including 4.1.14; from 4.2.0, up to and including 4.2.11; from 4.3.0, up to and including 4.3.8; from 4.4.0, up to and including 4.4.4

Published 2024-11-18. Last modified 2026-06-17.