Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-30884

Опубликовано: 18 мар. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds mod/customcert:manage in any single course can read and silently overwrite certificate elements belonging to any other course in the Moodle installation. The core_get_fragment callback editelement and the mod_customcert_save_element web service both fail to verify that the supplied elementid belongs to the authorized context, enabling cross-course information disclosure and data tampering. Versions 4.4.9 and 5.0.3 fix the issue.

EPSS

Процентиль: 6%
0.00168
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.6
fstec
5 месяцев назад

Уязвимость плагина moodle-mod_customcert виртуальной обучающей среды Moodle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 6%
0.00168
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-639