Moodle Improper Access Control Vulnerability in Course Overview Function

Vulnerability

A vulnerability exists in Moodle versions 5.0 to 5.0.2, where the course overview output function does not properly enforce user access permissions. This flaw could enable unauthorized users to access information about restricted courses, potentially revealing limited course details. The issue arises from insufficient handling of access control checks, allowing users with valid Moodle accounts to view metadata about courses they should not have access to.

Impact

Exploitation of this vulnerability could lead to unauthorized access to course information, including metadata about restricted courses.

Remediation

Users can upgrade to Moodle version 5.0.3 to address this vulnerability.

Added: Oct 23, 2025, 12:22 PM
Updated: Oct 23, 2025, 1:21 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.6
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.