Back to Database
Status published
Unknown
CVE-2024-38277
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Vulnerability Description
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38277
Credits & Attribution
No credits recorded in the NVD database.
References
- https://moodle.org/mod/forum/discuss.php?d=459502
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6/
More from Moodle
View All →CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows...
Medium
4.2
CVE-2025-34032
Moodle LMS Jmol Plugin Cross-site Scripting (XSS)
Medium
5.1
CVE-2025-34031
Moodle LMS Jmol Plugin Path Traversal
High
8.7
CVE-2024-38276
moodle: CSRF risks due to misuse of confirm_sesskey
Unknown
0
CVE-2024-38275
moodle: HTTP authorization header is preserved between "emulated redirects"
Unknown
0
Affected Vendor
Moodle
View all reports →Affected Software
Moodle
Vulnerable Versions:
4.4, 4.3, 4.2, 4.1
Timeline
Official Publish:
June 18th, 2024
Last Modified:
February 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.