BIT-moodle-2025-67848

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-67848.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-moodle-2025-67848
Aliases
Published
2026-02-12T08:51:00.880Z
Modified
2026-02-12T09:26:17.199364Z
Summary
Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.
Details

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.

Database specific
{
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.22
Introduced
4.4.0
Fixed
4.4.11
Introduced
4.5.0
Fixed
4.5.8
Introduced
5.0.0
Fixed
5.0.4
Introduced
5.1.0
Fixed
5.1.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-67848.json"