CVE-2023-23923: Moodle
High severity, CVSS 8.2. EPSS: 1% chance of exploitation in the next 30 days.
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
Affected products
- Moodle Moodle: from 3.9.0, before 3.9.19 (fixed in 3.9.19); from 3.11.0, before 3.11.12 (fixed in 3.11.12); from 4.0.0, before 4.0.6 (fixed in 4.0.6); version 4.1.0 only
Published 2023-02-17. Last modified 2026-06-17.