CVE-2025-32045: Moodle: hidden grades shown to users without permission on some grade reports
A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.
Other sources
Insufficient capability checks in some grade reports resulted in some hidden grades being available to users who did not have permission to view them.
Versions affected: 4.5 to 4.5.2, 4.4 to 4.4.6, 4.3 to 4.3.10, 4.1 to 4.1.16 and earlier unsupported versions Versions fixed: 4.5.3, 4.4.7, 4.3.11 and 4.1.17
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32045?
CVE-2025-32045 has a moderate severity rating due to the potential unauthorized access to hidden grades in Moodle.
How do I fix CVE-2025-32045?
To fix CVE-2025-32045, upgrade to Moodle version 4.5.3 or later, or the appropriate patched version for earlier releases.
What versions of Moodle are affected by CVE-2025-32045?
Moodle versions 4.1.16, 4.3.10, 4.4.6, and 4.5.2 are affected by CVE-2025-32045.
What type of vulnerability is CVE-2025-32045?
CVE-2025-32045 is a security vulnerability related to insufficient capability checks that can allow unauthorized access to grade reports.
What impact does CVE-2025-32045 have on user data?
CVE-2025-32045 can lead to unauthorized users viewing hidden grades, compromising the confidentiality of sensitive student information.