OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-102588

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

The vulnerability in Moodle's XML grade import feature allows an attacker to exploit inadequate CSRF token validation, enabling unauthorized grade modifications by tricking an authenticated user with grade management permissions into visiting a malicious site. This could lead to significant integrity issues within educational environments, as attackers can alter student grades without authorization. Educational institutions and organizations using Moodle should prioritize addressing this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-102588
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)