GHSA-w3pq-x3mm-4hh9MediumCVSS 6.5

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery ...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.

🔗 References (6)