CVE-2026-102588Medium· 6.5▾ SunlitA flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102581Medium· 4.6A flaw was found in Moodle
CVE-2026-102579Medium· 4.3A flaw was found in Moodle
CVE-2026-102577Medium· 4.3A flaw was found in Moodle
CVE-2026-102578Medium· 5.5A flaw was found in Moodle
CVE-2026-102585Medium· 4.3A flaw was found in Moodle
CVE-2026-102582Low· 2.2A flaw was found in Moodle