First published: Fri Apr 25 2025(Updated: )
A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-69m9-rprc-2x7g is considered medium due to the risks of de-anonymizing student submissions.
To fix GHSA-69m9-rprc-2x7g, update Moodle to version 4.5.4 or later.
Moodle versions from 4.5.0-beta to 4.5.4 are affected by GHSA-69m9-rprc-2x7g.
The impact of GHSA-69m9-rprc-2x7g is the potential exposure of student identities through de-anonymized assignment submissions.
Students who submit assignments anonymously in Moodle can be affected by GHSA-69m9-rprc-2x7g.