VYPR
Medium severity4.3OSV Advisory· Published Nov 20, 2024· Updated Jun 17, 2026

CVE-2024-48899

CVE-2024-48899

Description

A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 4.4.0-beta, < 4.4.34.4.3

Affected products

4
  • Moodle/Moodle2 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: >=4.4.0,<4.4.4
    • (no CPE)range: v4.4.0, v4.4.1, v4.4.2, …
  • osv-coords2 versions
    >= 4.4.0, < 4.4.4+ 1 more
    • (no CPE)range: >= 4.4.0, < 4.4.4
    • (no CPE)range: >= 4.4.0-beta, < 4.4.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.