VYPR
Medium severity4.3OSV Advisory· Published Nov 18, 2024· Updated Jun 17, 2026

CVE-2024-48896

CVE-2024-48896

Description

A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
< 4.1.144.1.14
moodle/moodlePackagist
>= 4.2.0, < 4.2.114.2.11
moodle/moodlePackagist
>= 4.3.0, < 4.3.84.3.8
moodle/moodlePackagist
>= 4.4.0, < 4.4.44.4.4

Affected products

4
  • Moodle/Moodle2 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: <=4.1.14
    • (no CPE)range: v1.0.0, v1.0.1, v1.0.2, …
  • osv-coords2 versions
    < 4.1.19+ 1 more
    • (no CPE)range: < 4.1.19
    • (no CPE)range: < 4.1.14

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.