CVE Vulnerabilities

CVE-2025-62398

Improper Authentication

Published: Oct 23, 2025 | Modified: Nov 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle4.4.0 (including)4.4.11 (excluding)
MoodleMoodle4.5.0 (including)4.5.7 (excluding)
MoodleMoodle5.0.0 (including)5.0.3 (excluding)

Potential Mitigations

References