Impact
A missing capability check in Moodle allows a low‑privileged authenticated user to trigger the recalculation of grade penalties, enabling that user to alter grade penalty records and potentially change student assessment scores. This flaw leads to a violation of data integrity by permitting unauthorized users to modify grades that should be protected.
Affected Systems
The vulnerability affects installations of Moodle. No specific affected versions are listed in the data, so any Moodle deployment subject to this lack of capability enforcement could be impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity, and the EPSS score is not provided, suggesting limited exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is that the user must be authenticated but with a low privilege level; the user can access the grade penalty recalculation function and modify data without the required permissions. No remote code execution or privilege escalation to administrative level is reported, but the integrity of assessment data is at risk.
OpenCVE Enrichment