Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5jv-w5cw-j9ff | Moodle authentication bypass vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 03 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted. | |
| Title | Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access. | |
| Weaknesses | CWE-280 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-04T04:55:50.381Z
Reserved: 2025-12-12T13:00:24.330Z
Link: CVE-2025-67848
Updated: 2026-02-03T17:01:09.336Z
Status : Awaiting Analysis
Published: 2026-02-03T11:15:54.107
Modified: 2026-02-03T16:44:03.343
Link: CVE-2025-67848
No data.
OpenCVE Enrichment
No data.
Github GHSA