CyberRota Analysis
AI-GeneratedA vulnerability in Moodle allows users with enrolment permissions to access the manual enrolment management page directly, even if the manual enrolment plugin has been disabled by an administrator. This oversight could lead to unauthorized management of enrolments, potentially compromising user access controls. Institutions using Moodle should prioritize addressing this issue to ensure proper enforcement of enrolment settings and maintain security integrity.
Original NVD Description
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.
Related CVEs
Other vulnerabilities affecting the same vendor(s)