CVE-2026-102588
Received Received - Intake

Cross-Site Request Forgery in Moodle Grade Import

Vulnerability report for CVE-2026-102588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in Moodle's XML grade import feature. It allows an attacker to trick an authenticated user with grade management permissions into visiting a malicious webpage. This triggers unauthorized requests that can set or overwrite student grades without proper authorization.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized XML grade import requests or unusual grade modification activities. Check Moodle logs for suspicious activity related to grade changes or CSRF token validation failures.

Impact Analysis

If you manage grades in Moodle, an attacker could exploit this to change student grades without your knowledge. This could lead to incorrect academic records, unfair advantages, or reputational damage for educational institutions. Users without grade management permissions are not directly affected.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized grade changes, which may violate data integrity requirements in GDPR or HIPAA. Accurate record-keeping is essential for compliance, and unauthorized modifications could lead to non-compliance penalties or legal issues for institutions.

Mitigation Strategies

Immediately update Moodle to the latest version to ensure proper CSRF token validation. Disable XML grade import functionality if not required. Educate users about phishing risks and restrict grade management permissions to trusted personnel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart