CVE-2018-1082: Moodle
High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.
Affected products
- Moodle Moodle: from 3.3.0, up to and including 3.3.4; from 3.4.0, up to and including 3.4.1
Published 2018-04-04. Last modified 2026-06-17.