Cross-Site Request Forgery Vulnerability in Moodle by Moodle
CVE-2026-102588

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102588?

A security flaw in Moodle's XML grade import feature lacks adequate validation for CSRF tokens. This vulnerability can be exploited by an attacker who tricks an authenticated user, holding grade management permissions, into visiting a malicious website. As a result, the attacker can execute unauthorized actions, such as setting or altering student grades without proper authorization, thereby compromising the integrity of the grading system.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Vincent Schneider as the original reporter.
.