CVE-2022-0334: Moodle
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
Affected products
- Moodle Moodle: up to and including 3.8.9; from 3.9.0, up to and including 3.9.11; from 3.10.0, before 3.10.9 (fixed in 3.10.9); from 3.11.0, before 3.11.5 (fixed in 3.11.5)
Published 2022-01-25. Last modified 2026-06-17.