Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN922
_____________________________________________________________________

DATE                : 23/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running Moodle versions prior to
                           5.2.3, 5.1.7, 5.0.10, 4.5.14.
  
=====================================================================
https://moodle.org/mod/forum/discuss.php?d=482607
https://moodle.org/mod/forum/discuss.php?d=482608
_____________________________________________________________________


MSA-26-0042: Blind SQL injection risk in profile availability
condition check
par Michael Hawkins, mardi 22 septembre 2026, 11:12


Insufficient validation of a profile availability condition check
resulted in a blind SQL injection risk being available to teachers
(and other privileged users such as admins).
Severity/Risk: 	Serious
Versions affected: 	5.2 to 5.2.2, 5.1 to 5.1.6, 5.0 to 5.0.9,
4.5 to 4.5.13 and earlier unsupported versions
Versions fixed: 	5.2.3, 5.1.7, 5.0.10 and 4.5.14
Reported by: 	Vincent Schneider
CVE identifier: 	Pending
Changes (main): 	http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89484
Tracker issue: 	MDL-89484 Blind SQL injection risk in profile
availability condition check

_____________________________________________________________________


MSA-26-0043: Possible to bypass the login notification mechanism
par Michael Hawkins, mardi 22 septembre 2026, 11:18


It was possible to bypass the login notification mechanism, so a user
would not be notified if their account received a new login. This
could make it easier for unauthorised users to log in without detection.
Note: Valid login credentials (such as username and password) were
still required.
Severity/Risk: 	Minor
Versions affected: 	5.2 to 5.2.2, 5.1 to 5.1.6, 5.0 to 5.0.9, 4.5
to 4.5.13 and earlier unsupported versions
Versions fixed: 	5.2.3, 5.1.7, 5.0.10 and 4.5.14
Reported by: 	Brendan Heywood
CVE identifier: 	Pending
Changes (main): 	http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-87817
Tracker issue: 	MDL-87817 Possible to bypass the login notification
mechanism


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




