CVE-2026-30884 | mdjnelson moodle-mod_customcert up to 4.4.8/5.0.2 core_get_fragment editelement/mod_customcert_save_element authorization (GHSA-8pjr-j7r4-ccjx)
A vulnerability was found in mdjnelson moodle-mod_customcert up to 4.4.8/5.0.2. It has been declared as critical. Affected by this issue is the function core_get_fragment. The manipulation of the argument editelement/mod_customcert_save_element results in authorization bypass.
This vulnerability is reported as CVE-2026-30884. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.