CVE-2024-3932 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Totara LMS versions up to 18.7, specifically within an unknown part of the User Selector component. The CVSS score is 3.1 (LOW), indicating a remote attack vector with high attack complexity and difficult exploitability, leading to a potential impact of low integrity. While public exploit disclosure exists, there is no evidence of active exploitation, readily available exploit code in common frameworks, or significant community discussion or media coverage. Upgrading to Totara LMS versions 13.46, 14.38, 15.33, 16.27, 17.21, or 18.8 remediates this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Totara | LMS | 13.0, 13.1, 13.10, 13.11, 13.12, 13.13, 13.14, 13.15, 13.16, 13.17, 13.18, 13.19, 13.2, 13.20, 13.21, 13.22, 13.23, 13.24, 13.25, 13.26, 13.27, 13.28, 13.29, 13.3, 13.30, 13.31, 13.32, 13.33, 13.34, 13.35, 13.36, 13.37, 13.38, 13.39, 13.4, 13.40, 13.41, 13.42, 13.43, 13.44, 13.45, 13.5, 13.6, 13.7, 13.8, 13.9, 14.0, 14.1, 14.10, 14.11, 14.12, 14.13, 14.14, 14.15, 14.16, 14.17, 14.18, 14.19, 14.2, 14.20, 14.21, 14.22, 14.23, 14.24, 14.25, 14.26, 14.27, 14.28, 14.29, 14.3, 14.30, 14.31, 14.32, 14.33, 14.34, 14.35, 14.36, 14.37, 14.4, 14.5, 14.6, 14.7, 14.8, 14.9, 15.0, 15.1, 15.10, 15.11, 15.12, 15.13, 15.14, 15.15, 15.16, 15.17, 15.18, 15.19, 15.2, 15.20, 15.21, 15.22, 15.23, 15.24, 15.25, 15.26, 15.27, 15.28, 15.29, 15.3, 15.30, 15.31, 15.32, 15.4, 15.5, 15.6, 15.7, 15.8, 15.9, 16.0, 16.1, 16.10, 16.11, 16.12, 16.13, 16.14, 16.15, 16.16, 16.17, 16.18, 16.19, 16.2, 16.20, 16.21, 16.22, 16.23, 16.24, 16.25, 16.26, 16.3, 16.4, 16.5, 16.6, 16.7, 16.8, 16.9, 17.0, 17.1, 17.10, 17.11, 17.12, 17.13, 17.14, 17.15, 17.16, 17.17, 17.18, 17.19, 17.2, 17.20, 17.3, 17.4, 17.5, 17.6, 17.7, 17.8, 17.9, 18.0, 18.1, 18.2, 18.3, 18.4, 18.5, 18.6, 18.7CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.