CVE Vulnerabilities

CVE-2025-62396

Exposure of Information Through Directory Listing

Published: Oct 23, 2025 | Modified: Nov 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 4.5.0 (including) 4.5.7 (excluding)
Moodle Moodle 5.0.0 (including) 5.0.3 (excluding)

Potential Mitigations

References