Impact
The flaw lies in the XML grade import feature of Moodle, which does not enforce a CSRF token before processing grade submissions (CWE-346). An attacker who can lure a logged‑in user with grade‑management rights to a malicious page can trigger the import operation in the victim's session, causing the server to accept and overwrite the selected student grades. This changes the integrity of academic records, allowing abuse such as grade manipulation for academic advantage or fraud. The vulnerability succeeds solely through a forged HTTP request; it does not require access to the Moodle source or server filesystem.
Affected Systems
All Moodle installations that expose the XML grade import capability are affected, regardless of the specific release version. The issue exists in any configuration where unprotected grade imports are enabled and does not depend on additional plugins or extensions.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the medium severity range, and because the EPSS score is unavailable, the exploitation likelihood is not quantified. It is not listed in the CISA KEV catalog. The attack vector is remote, requiring only that the victim is authenticated and has the proper permission set. An attacker can use a crafted link or payload to make the victim trigger the action without appearing to perform the group of operations. Once the request is sent, the server updates the target grades with no further interaction, making exploitation straightforward for a determined adversary.
OpenCVE Enrichment