← Back

CVE-2025-3625

nvd nist
Published: Apr 25, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Exploitability: 2.8 / Impact: 4.2
Source: patrick@puiterwijk.org (Secondary)

Description

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

Affected (3)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 4.3.0 to 4.3.12
From 4.4.0 to 4.4.8
From 4.5.0 to 4.5.4

References (2)

Source: patrick@puiterwijk.org
Third Party Advisory
Source: patrick@puiterwijk.org
Issue Tracking

Timeline

No history available yet.