Insecure Direct Object Reference in Moodle OpenAI Chat Block Plugin
CVE-2025-60511

4.3MEDIUM

Key Information:

Vendor

Moodle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-60511?

The Moodle OpenAI Chat Block plugin version 3.0.1 suffers from an Insecure Direct Object Reference (IDOR) vulnerability caused by inadequate validation of the blockId parameter in the API endpoint /blocks/openai_chat/api/completion.php. This issue allows an authenticated student to impersonate another user's block, such as that of an administrator, enabling them to send queries executed under the configuration of that block. As a result, sensitive administrator-only data may be exposed, the behavior of the model could be tampered with, and API resources may be misused.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.