Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Taka-Cst

#26738of 53,633
9.6Total CVSS
Vulnerabilities · 1
PT-2026-26023
9.6
2026-03-15
Moodle · Moodle · CVE-2026-30884
**Name of the Vulnerable Software and Affected Versions** mdjnelson/moodle-mod customcert versions prior to 4.4.9 and 5.0.3 **Description** The mdjnelson/moodle-mod customcert plugin for Moodle, used for creating dynamically generated certificates, contains a flaw where a teacher with the `mod/customcert:manage` permission in any course can read and silently overwrite certificate elements belonging to other courses within the Moodle installation. This occurs because the `core get fragment` callback `editelement` and the `mod customcert save element` web service do not verify that the supplied `elementid` belongs to the authorized context. This enables cross-course information disclosure and data tampering. The `elementid` parameter is vulnerable, allowing unauthorized access and modification of certificate data. **Recommendations** Versions prior to 4.4.9 should be updated to version 4.4.9 or later. Versions prior to 5.0.3 should be updated to version 5.0.3 or later.