CVE-2024-45691

CVE-2024-45691: Moodle: lesson activity password bypass through php loose comparison

Published November 20, 2024
Last update November 20, 2024

CVSS base score

What the vulnerability does

01Description

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.

Key dates

02Disclosure timeline

November 20, 2024 CVE published
November 20, 2024 Record updated