CVE-2018-1136: Moodle

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.

Affected products

  • Moodle Moodle: from 3.1.0, up to and including 3.1.11; from 3.2.0, up to and including 3.2.8; from 3.3.0, up to and including 3.3.5; from 3.4.0, up to and including 3.4.2

Published 2018-05-25. Last modified 2026-06-17.