Moodle Cohort Data Authorization Vulnerability

Vulnerability

An authorization flaw has been identified in Moodle, specifically in versions 4.5 prior to 4.5.4, 4.4 prior to 4.4.8, 4.3 prior to 4.3.12, 4.1 prior to 4.1.18, and earlier unsupported versions. The vulnerability allows users to access cohort data they are not authorized to retrieve, indicating an issue of incorrect authorization. This flaw could be exploited by users to fetch unauthorized cohort information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to cohort data, allowing users to view information they are not entitled to.

Remediation

Users can upgrade to Moodle versions 4.5.4, 4.4.8, 4.3.12 or 4.1.18 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.