Listen to this Post
The vulnerability, CVE-2025-22026, exists within the `course_output_fragment_course_overview` function in Moodle. This function is responsible for generating and returning the HTML fragment for a user’s course overview dashboard. The flaw is a missing authorization check. Before rendering the overview for a specific course, the function fails to adequately validate whether the currently authenticated user is explicitly enrolled or has the necessary capabilities to access that particular course. Instead, it may rely on a more general permission context or incorrectly assume the user is only requesting data for courses they are legally permitted to view. When a malicious user crafts a request targeting a course ID they do not have access to, the function processes the request without the proper security gate. Consequently, the server executes the logic to generate the course overview fragment and returns it in the response, thereby leaking limited information about a restricted course to an unauthorized actor.
Platform: Moodle
Version: Specific versions TBD
Vulnerability: Access Control Bypass
Severity: Moderate
date: 2024-10-23
Prediction: Patch by 2024-11-13
What Undercode Say:
Curl command to demonstrate the fragment request
curl -H "Cookie: MoodleSession=your_session" "https://vulnerable-moodle-site.com/lib/ajax/service.php?info=course_output_fragment_course_overview&args[bash][courseid]=12345"
Example PHP snippet highlighting the missing capability check
// Vulnerable code in /course/classes/output/course_overview.php
public function fragment_course_overview($courseid) {
// MISSING: require_capability('moodle/course:view', context_course::instance($courseid));
$course = get_course($courseid);
$renderer = $this->get_renderer();
return $renderer->render_course_overview($course);
}
How Exploit:
An attacker, possessing a standard user account, can systematically manipulate the ‘courseid’ parameter in AJAX requests to the `course_output_fragment_course_overview` endpoint. By substituting their own valid course IDs with those of hidden or restricted courses, they can retrieve and view the generated HTML overview fragments for those unauthorized courses, leading to information disclosure.
Protection from this CVE:
Apply the official vendor patch when released. As a temporary workaround, disable the affected course overview fragment functionality or implement a custom patch that adds a strict capability check (moodle/course:view) within the course context for the targeted course ID before any data is processed or rendered.
Impact:
Information Disclosure
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

