To address a cache poisoning risk in Moodle, additional validation for local storage was required.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-3180 Moodle vulnerable to cache poisoning via injection into storage
Github GHSA Github GHSA GHSA-2r9m-wg35-rfvc Moodle vulnerable to cache poisoning via injection into storage
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00022}

epss

{'score': 0.00024}


Mon, 10 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Weaknesses CWE-345
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 Nov 2024 13:30:00 +0000

Type Values Removed Values Added
Description To address a cache poisoning risk in Moodle, additional validation for local storage was required.
Title Moodle: cache poisoning via injection into storage
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-02-10T22:26:35.081Z

Reserved: 2024-08-13T07:15:00.598Z

Link: CVE-2024-43428

cve-icon Vulnrichment

Updated: 2024-11-07T14:42:53.999Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-07T14:15:15.703

Modified: 2025-05-01T16:01:48.570

Link: CVE-2024-43428

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.