Impact
A flaw was discovered in the Moodle grade web service where an incorrect capability check allows an authenticated student to view the profile information of other students in the same course. This vulnerability leads to unauthorized disclosure of personal data. Based on the description, the attack vector is an authenticated user utilizing the web service; the attacker must be logged in to the Moodle environment and enrolled in the target course.
Affected Systems
The affected product is Moodle, specifically its web-based grade web service functionality. No specific version numbers are listed in the data, so any Moodle installation that has not yet incorporated the fix through an update may be vulnerable.
Risk and Exploitability
The CVSS score is 4.3, indicating low severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely to occur on a large scale. An attacker would need to authenticate as a student with enrollment in the relevant course, then invoke the grade web service; if the correct role permissions are not enforced, the student's profile data becomes visible.
OpenCVE Enrichment