Impact
Moodle does not verify that an assigned group belongs to the target course when a teacher enrolls a user. This omission lets an authenticated teacher add a user to any group in any course, effectively giving the user access to courses they should not be able to view. The resulting privilege escalation can expose confidential course material to unauthorized users and violate institutional access controls.
Affected Systems
Any Moodle installation that uses the standard enrollment and group assignment functions and grants teachers the ability to assign a user to a group. No specific version is listed, so the vulnerability may be present in all releases that incorporate the code path affected by commit MDL-88538 until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, so the probability of exploitation is unknown, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an authenticated teacher acting within the Moodle web interface; the attack requires no elevated system privileges but does require teacher-level access. Because the teacher can choose any group in any course, the potential impact spans multiple courses and users.
OpenCVE Enrichment