Description

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's block (e.g., administrator) and send queries that are executed with that block's configuration. This can expose administrator-only Source of Truth entries, alter model behavior, and potentially misuse API resources.

INFO

Published Date :

2025-10-21T00:00:00.000Z

Last Modified :

2025-10-21T18:35:59.606Z

Source :

mitre

Researchers

Following researchers has claimed that they have found this vulnerability.

Onurcan Genç

@onurcangnc

AFFECTED PRODUCTS

The following products are affected by CVE-2025-60511 vulnerability.

Vendors Products
Moodle
  • Moodle

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact