CVE-2025-3640
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: patrick@puiterwijk.org (Secondary)
Description
A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.
Affected (4)
References (3)
Source: patrick@puiterwijk.org
Third Party Advisory
Timeline
No history available yet.