Moodle Self-Enrolment Vulnerability Bypassing Multi-Factor Authentication

Vulnerability

A vulnerability in Moodle allows students to self-enrol in courses without completing all required safety checks, particularly in relation to multi-factor authentication (MFA). Affected users can sign up for courses before finishing the two-step verification process. This issue is present in Moodle versions 4.5 prior to 4.5.4, 4.4 prior to 4.4.8, and 4.3 prior to 4.3.12.

Impact

Exploitation of this vulnerability could lead to improper authentication, allowing users to bypass MFA requirements and enrol in courses prematurely.

Remediation

Users can upgrade to Moodle versions 4.5.4, 4.4.8, or 4.3.12 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
6.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.