First published: Fri Apr 25 2025(Updated: )
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-qhc7-xhc2-7p7w is considered medium due to the risk of unauthorized course enrollments.
To fix GHSA-qhc7-xhc2-7p7w, update Moodle to version 4.5.4, 4.4.8, or 4.3.12.
GHSA-qhc7-xhc2-7p7w exposes the risk of students enrolling in courses without completing safety checks.
Moodle versions 4.5.0 to 4.5.4, 4.4.0 to 4.4.8, and 4.3.0 to 4.3.12 are affected by GHSA-qhc7-xhc2-7p7w.
GHSA-qhc7-xhc2-7p7w allows users to bypass two-step verification, leading to potential unauthorized access to course materials.