GHSA-p9cx-f595-h79h
GitHub Security Advisory
Moodle's IDOR in Feedback non-respondents report allows messaging arbitrary site users
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
Affected Packages
Packagist
moodle/moodle
Affected versions:
0
(fixed in 4.1.12)
Packagist
moodle/moodle
Affected versions:
4.2.0-beta
(fixed in 4.2.9)
Packagist
moodle/moodle
Affected versions:
4.3.0-beta
(fixed in 4.3.6)
Packagist
moodle/moodle
Affected versions:
4.4.0-beta
(fixed in 4.4.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.