Hello,

3.9.2 is a very old version. The latest in that minor release is from 8
Dec 2023 (3.9.25). According to
https://download.moodle.org/releases/security/ it does not even have
Security Support any more.

Is this Behaviour reproducible in at least Moodle 4.1.22? If not I
don't think a CVE should be issued here, since it would only increase
the Noise. The Influx of CVE's and advisory is high as is and I don't
think it's beneficial to issue even more for software version that are
way beyond EOL.

On Mon, 2026-09-28 at 22:34 +0500, Muhammad Arslan Official wrote:
> Hello,
> 
> I am disclosing a vulnerability in Moodle LMS and requesting a CVE
> ID, as the vendor (a registered CNA) has not assigned one after
> coordinated disclosure, and a MITRE CNA-LR request (CAN-2026-2032565)
> has been under review for ~3 months without response.
> 
> Product: Moodle LMS
> Confirmed version: 3.9.2 (other versions not yet verified)
> Class: CWE-434 / CWE-20 - Unrestricted file upload / improper input
> validation
> Privilege required: authenticated, Student-level account
> Vendor status: reported via Bugcrowd 2025-08-31, triaged P3 (2025-09-
> 06);
> vendor acknowledged the behaviour but has not assigned a CVE or
> committed to a code fix.

Kind Regards

Michael







Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to