2.7
CVE-2026-102583
- EPSS 0.24%
- Veröffentlicht 30.09.2026 08:36:12
- Zuletzt bearbeitet 01.10.2026 15:15:21
- Erkennungen
Moodle: incorrect capability check in ai generate image web service
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.132 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| patrick@puiterwijk.org | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
|
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
https://moodle.org/mod/forum/discuss.php?d=482501
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587
https://access.redhat.com/security/cve/CVE-2026-102583
https://bugzilla.redhat.com/show_bug.cgi?id=2543640