Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-30884 โ€” AI Deep Analysis Summary

CVSS 9.6 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: A critical authorization flaw in the **Custom Certificate Activity** plugin for Moodle.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-639: Authorization Bypass Through User-Controlled Key**.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Affected**: Plugin **moodle-mod_customcert** by vendor **mdjnelson**. ๐Ÿ“‰ **Versions**: All versions **< 4.4.9** AND all versions **< 5.0.3**. If you are on an older version, you are at risk! โš ๏ธ

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Actions**: With low privileges, hackers can: 1. **Read** sensitive data from other courses (Info Leakage). 2. **Modify** certificate elements (Data Tampering).โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Exploitation Threshold**: **Low**. CVSS indicates **AV:N** (Network), **AC:L** (Low Complexity), **PR:L** (Low Privileges required).โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ•ต๏ธ **Public Exploit**: **No**. The `pocs` field is empty. ๐Ÿšซ While GitHub advisories exist, there is no confirmed public Proof-of-Concept (PoC) or wild exploitation script available yet. Stay vigilant!

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: 1. Check your Moodle plugin list for **Custom Certificate Activity**. 2. Verify the version number. ๐Ÿ“Š Is it **4.4.8 or lower**? Or **5.0.2 or lower**? If yes, you are vulnerable.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Official Fix**: **Yes**. Updates are available. ๐Ÿš€ Upgrade to **v4.4.9+** or **v5.0.3+**. The vendor has released commits (e.g., `ddc8f01`, `a1494a8`) to patch the authorization logic.โ€ฆ

Q9What if no patch? (Workaround)

๐Ÿ›‘ **No Patch Workaround**: If you cannot update immediately: 1. **Disable** the Custom Certificate Activity plugin temporarily. ๐Ÿšซ 2. Restrict access to the Web Service endpoints if possible. 3.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **HIGH**. CVSS Score implies **High** Impact on Confidentiality and Integrity. ๐Ÿ“ˆ Even though auth is 'Low', the impact is severe.โ€ฆ