Moodle RSS Block Improper Access Control Vulnerability

Vulnerability

An access control vulnerability has been identified in Moodle's RSS block feature. This issue allows unauthorized users to view RSS feeds due to inadequate permission checks. The vulnerability affects Moodle versions 4.5 prior to 4.5.4, 4.4 prior to 4.4.8, 4.3 prior to 4.3.12, 4.1 prior to 4.1.18, and earlier unsupported versions.

Impact

Exploitation of this vulnerability leads to unauthorized access to RSS feeds, allowing users to view content that should be restricted.

Remediation

Users can upgrade to Moodle versions 4.5.4, 4.4.8, 4.3.12, or 4.1.18 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.