CVE-2024-45691
MEDIUMDescription
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
Is your site exposed to CVE-2024-45691?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| moodle | moodle |
| moodle | moodle |
| moodle | moodle |
| moodle | moodle |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-45691? +
How severe is CVE-2024-45691? +
What products are affected by CVE-2024-45691? +
How do I check if I'm vulnerable to CVE-2024-45691? +
Related Vulnerabilities
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
Incorrect CSRF token checks resulted in multiple CSRF risks.
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By …
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By …
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged …