Executive brief
The Moodle OpenAI Chat Block plugin, which allows users to interact with AI models within the Moodle learning platform, contains a security flaw. An authenticated user, such as a student, can manipulate requests to access chat configurations belonging to other users, including administrators. This could allow unauthorized users to view sensitive 'Source of Truth' data, access restricted AI models, or impersonate administrative AI personas, potentially leading to the exposure of private information or misuse of expensive API resources.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Moodle OpenAI Chat Block plugin v3.0.1 (Build: 2025021700) within the /blocks/openai_chat/api/completion.php endpoint. The application fails to perform sufficient access control validation on the 'blockId' parameter provided in POST requests. An authenticated attacker (e.g., a student) can supply a 'blockId' belonging to another user, such as an administrator, to execute OpenAI completions using that user's specific configuration. This includes access to restricted prompt templates, 'Source of Truth' entries, and potentially higher-cost models (like GPT-4) configured for administrative use. The vulnerability allows for unauthorized information disclosure and resource consumption.
Affected products
- Moodle OpenAI Chat Block plugin (block_openai_chat) 3.0.1 (2025021700)
Timeline
- 2025-10-21: advisory: NVD published date