CVE Vulnerabilities

CVE-2026-102588

Origin Validation Error

Published: Sep 30, 2026 | Modified: Oct 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victims behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle*4.5.13 (excluding)
MoodleMoodle5.0.0 (including)5.0.9 (excluding)
MoodleMoodle5.1.0 (including)5.1.6 (excluding)
MoodleMoodle5.2.0 (including)5.2.2 (excluding)

References