Listen to this Post
The CVE-2025-22019 vulnerability stems from an improper access control flaw within Moodle’s messaging component for quiz notifications. The system’s logic for dispatching quiz-related messages, such as attempt submission confirmations, did not correctly validate a user’s current enrolment status before sending. Specifically, the code responsible for building the recipient list for these messages failed to cross-reference the user list with the active enrolment records. This omission meant that users whose enrolment in a course was suspended or set to inactive were not filtered out. Consequently, these inactive users received automated quiz messages, which constitute an information leak. The leaked information, while limited, confirms the existence of the quiz and the user’s prior association with the course, potentially revealing internal course structure or activity.
Platform: Moodle
Version: 5.0.0 – 5.0.2
Vulnerability: Information Leak
Severity: Moderate
date: 2025-10-23
Prediction: Patch available
What Undercode Say:
Querying for user enrolment status in a course moosh user-enrol-info -c <course_id> <user_id> Checking Moodle log for message sending events grep "quiz_message_sent" /path/to/moodledata/log/.log
// Example code snippet checking enrolment (conceptual) $context = context_course::instance($course->id); $enrolled_users = get_enrolled_users($context, '', 0, 'u.', null, 0, 0, true); // 'true' for active-only
How Exploit:
An attacker with teacher or manager permissions could intentionally suspend a user’s enrolment. When a quiz event subsequently triggers a notification, the suspended user will receive the message, confirming their residual access to course data and leaking quiz activity.
Protection from this CVE:
Upgrade to Moodle versions 5.0.3 or 4.5.7, which contain the necessary patches to ensure enrolment status is correctly validated before sending any quiz-related communications.
Impact:
Limited information disclosure. Inactive or suspended users receive quiz messages, revealing the existence and timing of course quizzes, a potential privacy concern.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

