CVE Vulnerabilities

CVE-2025-3627

Improper Authentication

Published: Apr 25, 2025 | Modified: Jun 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle4.3.0 (including)4.3.12 (excluding)
MoodleMoodle4.4.0 (including)4.4.8 (excluding)
MoodleMoodle4.5.0 (including)4.5.4 (excluding)

Potential Mitigations

References