Sceawere

Vulnerability Detail

CVE-2026-102588UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle CSRF Grade Manipulation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T09:17:16.163Z",
  "pubdate": "2026-09-30T09:17:16.163Z",
  "executiveSummary": "A Cross-Site Request Forgery (CSRF) vulnerability exists within the XML grade import feature of Moodle, allowing unauthorized manipulation of student assessment data. The vulnerability arises from an absence of mandatory CSRF token validation during the import process, which is designed to prevent unauthorized state-changing operations.\nThis flaw enables a remote attacker to perform unauthorized actions by leveraging the authenticated session of a user with grade management privileges. By crafting a malicious webpage or script, an attacker can coerce an unsuspecting, authenticated administrator or instructor into involuntarily executing grade import requests.\nThe primary risk implication is the compromise of academic integrity, as an attacker can arbitrarily set or overwrite student grades. Successful exploitation requires the victim to possess high-level privileges—specifically those authorized to manage grades—and necessitates active interaction with the malicious external content while a valid Moodle session is ongoing. The attack is network-exploitable and poses a significant risk to institutions relying on the accuracy of grade management systems within Moodle.",
  "technicalDetails": "The vulnerability resides in the XML grade import functionality of Moodle. The root cause is the failure to implement or validate CSRF tokens for state-changing HTTP requests. In standard web application architecture, CSRF tokens serve as an essential cryptographic defense, ensuring that requests originate from the legitimate application interface rather than a third-party source.\nThe exploitation flow initiates when an authenticated user with grade management permissions visits a third-party, attacker-controlled domain. This malicious webpage contains a hidden form, an automated fetch request, or an injected script configured to send a POST request to the Moodle grade import endpoint. Because the browser automatically attaches the victim's Moodle session cookies to the request, the server incorrectly validates the session and processes the XML data as if it were a legitimate user intent.\nSpecifically, the XML grade import endpoint lacks the necessary logic to compare a unique, cryptographically secure token submitted in the request against the expected token stored in the user's session data. As a result, the application fails to verify the origin of the request, permitting the processing of the attacker-supplied XML payload. This payload can contain arbitrary grade values mapped to student identifiers within the Moodle system.\nThe attack is highly effective because it bypasses the need for the attacker to authenticate directly into the system. Instead, the attacker piggybacks on the existing authorization of the victim. The post-exploitation impact is the persistent modification of database records pertaining to student grading, leading to potential academic fraud. This vulnerability is particularly dangerous as it leaves minimal server-side logs indicating that the action was performed by an external entity, as all requests appear to originate from the legitimate user's active session. This issue highlights a lack of 'Defense in Depth' for administrative functions within the XML import handler, which should enforce strict token verification on all mutation operations, regardless of the apparent authentication state."
}
CVE-2026-102588: Moodle CSRF Grade Manipulation (MEDIUM Severity, CVSS: 6.5) | Sceawere