Impact
A flaw in Moodle’s manual enrolment management page failed to verify whether the manual enrolment plugin was disabled, letting users with enrolment permissions bypass the administrative setting by navigating directly to the page’s URL and modify enrolments even after the feature had been turned off. This bypass enables an authorized user to perform actions outside the intended scope, constituting a privilege escalation problem aligned with CWE‑425.
Affected Systems
The vulnerability affects Moodle installations that rely on the manual enrolment plugin. No specific version of Moodle is listed in the advisory, so any deployment using the plugin and running a version that has not yet applied the corrective change is potentially impacted. Administrators should review their current Moodle version and confirm whether the patch is included.
Risk and Exploitability
The CVSS score of 2.2 indicates low severity, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires an authenticated user with enrolment permissions, the exploitation vector is likely internal or requires compromised credentials. While the risk to confidentiality, integrity, or availability is modest, the ability to override administrative intent could be significant in environments with strict enrolment controls. Therefore, the recommended approach is to apply the vendor fix promptly and limit enrolment permissions to trusted administrators.
OpenCVE Enrichment