CVE-2024-43427

A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

01 May 2025, 16:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.7
First Time Moodle
Moodle moodle
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
References () https://bugzilla.redhat.com/show_bug.cgi?id=2304255 - () https://bugzilla.redhat.com/show_bug.cgi?id=2304255 - Permissions Required
References () https://moodle.org/mod/forum/discuss.php?d=461195 - () https://moodle.org/mod/forum/discuss.php?d=461195 - Vendor Advisory

11 Nov 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 13:15

Updated : 2025-05-01 16:07


NVD link : CVE-2024-43427

Mitre link : CVE-2024-43427


JSON object : View

Products Affected

moodle

  • moodle
CWE

No CWE.