What happened
NVD published (CVSS 2.7) an incorrect-capability-check flaw allowing unauthorized use of the AI image generation feature. Low-impact authorization gap in an education platform's AI tooling.
Why it matters
Bypasses AI feature entitlement/quotas and any abuse controls tied to the missing capability in LMS AI deployments.
Attack vector
An authenticated user calls the AI editor's image-generation web service directly, bypassing the capability check that should restrict who may use the AI feature, consuming paid/limited AI quota.
Affected systems
Moodle affected AI editor placement (image generation web service; fixed per MDL-88587)
Mitigation
Apply the Moodle fix per MDL-88587 (capability check in AI editor placement image generation).