Medium severity4.3NVD Advisory· Published Mar 24, 2023· Updated Jun 17, 2026
CVE-2022-40208
CVE-2022-40208
Description
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 4.0.0, < 4.0.3 | 4.0.3 |
moodle/moodlePackagist | >= 3.11.0, < 3.11.9 | 3.11.9 |
moodle/moodlePackagist | < 3.9.16 | 3.9.16 |
Affected products
7- osv-coords2 versions
>= 3.9.0, < 3.9.16+ 1 more
- (no CPE)range: >= 3.9.0, < 3.9.16
- (no CPE)range: >= 4.0.0, < 4.0.3
Patches
Vulnerability mechanics
References
5- moodle.org/mod/forum/discuss.phpnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-948f-j464-rfj2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-40208ghsaADVISORY
- git.moodle.org/gwghsaWEB
- github.com/moodle/moodle/commit/025e0297b65e6a8bd61efad0fdf36168c613f918ghsaWEB
News mentions
0No linked articles in our index yet.