CVE-2023-1402: Moodle
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
Affected products
- Moodle Moodle: after 3.9.0, before 3.9.20 (fixed in 3.9.20); after 3.11.0, before 3.11.13 (fixed in 3.11.13); after 4.0.0, before 4.0.7 (fixed in 4.0.7); version 3.9.0 only; version 3.11.0 only; version 4.0.0 only; …
Published 2023-03-23. Last modified 2026-06-17.