-
CVSS Score
-The vulnerability stems from insufficient access control in Quiz external API methods. The Moodle security advisory (MSA-24-0031) explicitly links the issue to external methods for quiz overrides. The Git commits (MDL-82633) show fixes involving visibility checks and filtering for overrides in external methods. These functions are part of Moodle's external API infrastructure (mod/quiz/classes/external.php), which handles override management. The lack of proper permission validation in these methods aligns with the CWE-276 (incorrect default permissions) and the described vulnerability impact.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 4.4.0, < 4.4.2 | 4.4.2 |
A Semantic Attack on Google Gemini - Read the Latest Research