Impact
The vulnerability in Moodle’s AI image generation web service arises from an incorrect capability check. An authenticated user who does not possess the necessary capability can trigger image generation. This allows unauthorized AI‑generated content to be created without prior permission. The weakness is identified as improper authorization (CWE‑425).
Affected Systems
All Moodle deployments that include the AI image generation feature are potentially affected. No specific version restrictions are disclosed, implying that any current or future release that implements the web service may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 2.7 classifies the flaw as low severity. EPSS is not available, so the potential for exploitation is unclear but likely modest. The attack requires an authenticated account; an attacker must first obtain valid credentials. Based on the description, there is no explicit indication that the flaw provides arbitrary code execution or direct data compromise. The vulnerability enables privileged AI image generation beyond what the user is authorized to perform, but does not appear to expose sensitive data or allow broader system compromise. Since the flaw is not listed in CISA’s KEV catalog, no active exploitation has been reported.
OpenCVE Enrichment