Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 4.5, <= 4.5.1
- >= 4.4, <= 4.4.5
- >= 4.3, <= 4.3.9
- >= 4.1, <= 4.1.15
A vulnerability exists in Moodle that allows users to discover non-searchable tags through the tag search page or in the tags block. This issue affects Moodle versions 4.5 prior to 4.5.1, 4.4 prior to 4.4.5, 4.3 prior to 4.3.9, 4.1 prior to 4.1.15, and earlier unsupported versions. The vulnerability arises because tags that are not meant to be visible can still be accessed by users via these channels.
Exploitation of this vulnerability could lead to the unintended exposure of tags that are meant to be private or unsearchable, potentially revealing sensitive information or disrupting user experience.
Users can upgrade to Moodle versions 4.5.2, 4.4.6, 4.3.10, or 4.1.16 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.