PT-2026-60486 · Moodle · Office 365 Integration
CVE-2026-54733
·
Published
2026-07-16
·
Updated
2026-07-17
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 365 Integration plugin versions prior to 4.5.6
Microsoft Office 365 Integration plugin versions prior to 5.0.5
Microsoft Office 365 Integration plugin versions prior to 5.1.1
Description
The Microsoft Office 365 Integration plugin for Moodle fails to verify the JWT (JSON Web Token) signature when processing the
sso login.php endpoint. An unauthenticated attacker can base64-decode a JWT payload and forge a token using the upn claim to obtain a Moodle session as an authenticated Office 365 user.Recommendations
Update to version 4.5.6.
Update to version 5.0.5.
Update to version 5.1.1.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office 365 Integration