CVE-2024-43438: Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users
A flaw was found in Feedback. Bulk messaging in the activity’s non-respondents report did not verify message recipients belonging to the set of users returned by the report.
References
Detect and mitigate CVE-2024-43438 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →