CVE-2024-48896
Estado: AnalizadaMedia (4.3)—
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-209
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-48896",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-48896",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-18T14:57:51.103180Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "4.4.0",
"lessThan": "4.4.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.3.0",
"lessThan": "4.3.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.2.0",
"lessThan": "4.2.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.1.0",
"lessThan": "4.1.14",
"versionType": "semver"
},
{
"status": "affected",
"version": "0",
"lessThan": "4.1.0",
"versionType": "semver"
}
],
"packageName": "moodle",
"collectionURL": "https://moodle.org/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-11-18T12:15:18.093",
"references": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318822",
"tags": [
"Issue Tracking"
],
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in Moodle. It is possible for users with the \"send message\" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site."
},
{
"lang": "es",
"value": "Se encontró una vulnerabilidad en Moodle. Es posible que los usuarios con la función \"enviar mensaje\" vean los nombres de otros usuarios a los que de otra manera no podrían acceder mediante un mensaje de error en Mensajería. Nota: El nombre que se devuelve sigue el formato de nombre completo configurado en el sitio."
}
],
"lastModified": "2026-06-17T07:58:59.387",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2D74BD7-3907-49E1-B2FC-A45108CB5AF0",
"versionEndIncluding": "4.1.14"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCE4F475-9272-4891-B690-3AB9720CD2D8",
"versionEndIncluding": "4.2.11",
"versionStartIncluding": "4.2.0"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6A31566-F7AD-4FD4-82A6-CCE0D52123B8",
"versionEndIncluding": "4.3.8",
"versionStartIncluding": "4.3.0"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E073E9C6-D72C-4C82-92AF-6C02B81EB28B",
"versionEndIncluding": "4.4.4",
"versionStartIncluding": "4.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}