Description
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized grade modification via CSRF
Action: Patch Immediately
AI Analysis

Impact

The flaw lies in the XML grade import feature of Moodle, which does not enforce a CSRF token before processing grade submissions (CWE-346). An attacker who can lure a logged‑in user with grade‑management rights to a malicious page can trigger the import operation in the victim's session, causing the server to accept and overwrite the selected student grades. This changes the integrity of academic records, allowing abuse such as grade manipulation for academic advantage or fraud. The vulnerability succeeds solely through a forged HTTP request; it does not require access to the Moodle source or server filesystem.

Affected Systems

All Moodle installations that expose the XML grade import capability are affected, regardless of the specific release version. The issue exists in any configuration where unprotected grade imports are enabled and does not depend on additional plugins or extensions.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the medium severity range, and because the EPSS score is unavailable, the exploitation likelihood is not quantified. It is not listed in the CISA KEV catalog. The attack vector is remote, requiring only that the victim is authenticated and has the proper permission set. An attacker can use a crafted link or payload to make the victim trigger the action without appearing to perform the group of operations. Once the request is sent, the server updates the target grades with no further interaction, making exploitation straightforward for a determined adversary.

Generated by OpenCVE AI on September 30, 2026 at 12:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Moodle to a release that implements CSRF protection for the XML grade import feature.
  • Disable or remove the XML grade import capability for users who do not hold grade‑management permissions.
  • Ensure that all forms, including hidden or automated imports, validate CSRF tokens and consider applying a strict Content Security Policy to limit cross‑site request execution.

Generated by OpenCVE AI on September 30, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
Title Moodle: csrf in xml grade import
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T08:36:23.737Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102588

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:16.163

Modified: 2026-09-30T09:17:16.163

Link: CVE-2026-102588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses