天下漏洞,尽知其名
MEDIUM

CVE-2026-102585 Moodle 权限校验不当漏洞

影响教师权限用户可越权将用户加入未授权课程的群组

AI 研判

Moodle 在将用户选课并分配到群组时,未校验所选群组是否属于该课程。拥有教师权限的已认证用户可借此绕过授权,把用户加入其无权访问课程中的群组。

影响范围

Moodle

受影响版本范围暂无公开信息,建议以官方安全公告为准。

漏洞详情

漏洞属于权限校验不当(授权缺失)。成因是选课并分配群组的流程中缺少对群组与课程归属关系的验证。攻击者以教师身份提交构造请求,即可将用户加入不属于其权限范围的课程群组。

利用条件与风险

利用前提是攻击者拥有教师权限的已认证账号;实战中可造成越权访问与数据泄露,CVSS 4.3 属中危。

修复建议

官方修复方案暂无公开信息,建议关注 Moodle 官方安全公告并及时升级;临时缓解可限制教师账号权限并审计异常选课/群组分配操作。

原始情报

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.