Listen to this Post
The CVE-2025-22086 vulnerability in Moodle stems from an access control flaw within the calendar event creation logic. When a user with the capability to create calendar events attempts to associate an event with a group, the system would present a list of available groups. The vulnerability occurred because the function responsible for generating this list did not properly check the user’s permissions against groups that had their visibility set to “hidden.” Consequently, while users without ‘moodle/site:accessallgroups’ permission could not see the members of these hidden groups, the group names themselves were inadvertently disclosed in the selection interface. This information leak exposed the existence and names of groups intended to be private, violating the intended security model and potentially revealing sensitive organizational structures or project details.
Platform: Moodle
Version: 4.1.21, 4.4.11, 4.5.7, 5.0.3
Vulnerability: Information Disclosure
Severity: Moderate
date: 2024-10-23
Prediction: 2024-11-06
What Undercode Say:
grep -r "get_available_groups" /path/to/moodle/
// Code snippet illustrating the flawed permission check
$allowedgroups = groups_get_available_groups($courseid);
// Missing specific check for 'groups:viewhiddengroups' capability
foreach ($allowedgroups as $group) {
// Group name is added to list regardless of visibility setting
}
How Exploit:
1. User enrolls in course.
2. Gains event creation rights.
3. Initiates new calendar event.
4. Triggers group selection list.
5. Observes hidden group names.
Protection from this CVE
Update Moodle to versions 4.1.21, 4.4.11, 4.5.7, or 5.0.3. For immediate mitigation, revoke the ‘moodle/calendar:manageentries’ capability from users who should not have broad visibility. Implement additional logic to filter group lists using ‘groups_get_available_groups’ with the ‘onlyenrolled’ and ‘withcapability’ parameters, explicitly checking for ‘moodle/site:accessallgroups’ or a custom ‘viewhiddengroups’ capability before displaying any group name.
Impact:
Unauthorized information disclosure, privacy violation, exposure of confidential group structures, potential for social engineering, and data protection compliance issues.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

