CVE-2018-1082: Moodle

High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.

A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

Affected products

  • Moodle Moodle: from 3.3.0, up to and including 3.3.4; from 3.4.0, up to and including 3.4.1

Published 2018-04-04. Last modified 2026-06-17.