Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 4.5, <= 4.5.3
- >= 4.4, <= 4.4.7
- >= 4.3, <= 4.3.11
A vulnerability in Moodle allows students to self-enrol in courses without completing all required safety checks, particularly in relation to multi-factor authentication (MFA). Affected users can sign up for courses before finishing the two-step verification process. This issue is present in Moodle versions 4.5 prior to 4.5.4, 4.4 prior to 4.4.8, and 4.3 prior to 4.3.12.
Exploitation of this vulnerability could lead to improper authentication, allowing users to bypass MFA requirements and enrol in courses prematurely.
Users can upgrade to Moodle versions 4.5.4, 4.4.8, or 4.3.12 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.