CVE-2024-45691
MEDIUMDescription
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
Is your site exposed to CVE-2024-45691?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| moodle | moodle |
| moodle | moodle |
| moodle | moodle |
| moodle | moodle |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-45691? +
How severe is CVE-2024-45691? +
What products are affected by CVE-2024-45691? +
How do I check if I'm vulnerable to CVE-2024-45691? +
Related Vulnerabilities
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By …
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token …
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By …
Incorrect CSRF token checks resulted in multiple CSRF risks.