Moodle Calendar Event Creation Privilege Escalation Vulnerability

Vulnerability

A vulnerability in Moodle allows users with permission to create calendar events to see the names of hidden groups. This issue arises because the event creation process lacks proper capability checks, inadvertently exposing private group information that should remain confidential within a course. The vulnerability affects Moodle versions 5.0 prior to 5.0.3, 4.5 prior to 4.5.7, 4.4 prior to 4.4.11, 4.1 prior to 4.1.21, and earlier unsupported versions.

Impact

Exploitation of this vulnerability could lead to unauthorized exposure of sensitive group information, including private or restricted group names.

Remediation

Users can upgrade to Moodle versions 5.0.3, 4.5.7, 4.4.11, or 4.1.21 to address this vulnerability.

Added: Oct 23, 2025, 12:18 PM
Updated: Oct 23, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
6.6
remediation
7.7
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.