CVE-2023-23923: Moodle

High severity, CVSS 8.2. EPSS: 1% chance of exploitation in the next 30 days.

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

Affected products

  • Moodle Moodle: from 3.9.0, before 3.9.19 (fixed in 3.9.19); from 3.11.0, before 3.11.12 (fixed in 3.11.12); from 4.0.0, before 4.0.6 (fixed in 4.0.6); version 4.1.0 only

Published 2023-02-17. Last modified 2026-06-17.