Executive brief
Joomdle, a Joomla extension used to integrate the Moodle learning management system, contains a security flaw due to an insecure default configuration. This vulnerability allows unauthorized individuals to read sensitive user account information and perform password resets on CMS accounts. An exploit could lead to full account takeover, compromising student data and administrative control over the learning platform.
Technical details
Joomdle versions prior to 3.1.1 (specifically 0.7.0 through 3.0.1) suffer from an insecure default initialization (CWE-1188) and exposure of sensitive information (CWE-200). The default configuration of the extension fails to properly restrict access to account management functions, allowing a network-based attacker to read CMS account details and trigger password resets. This effectively bypasses authentication controls for Joomla accounts integrated via the Joomdle component. The issue is resolved in version 3.1.1.
Affected products
- joomdle.com Joomdle 0.7.0 - 3.0.1
Timeline
- 2026-07-28: advisory
- 2026-07-28: disclosed