CyberRota Analysis
AI-GeneratedA vulnerability exists in Moodle that allows authenticated users with teacher privileges to enroll users into groups that do not belong to the course they are managing. This flaw could lead to unauthorized access to course materials and sensitive information, posing a risk to the integrity of course management. Educational institutions and organizations using Moodle should prioritize addressing this issue to safeguard against potential misuse.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)