First published: Tue Apr 15 2025(Updated: )
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=4.5<=4.5.3>=4.4<=4.4.7>=4.3<=4.3.11 | |
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3627 has been classified as a medium severity vulnerability.
To fix CVE-2025-3627, update Moodle to version 4.5.4, 4.4.8, or 4.3.12 depending on your current version.
CVE-2025-3627 affects Moodle versions 4.5.0 to 4.5.3, 4.4.0 to 4.4.7, and 4.3.0 to 4.3.11.
CVE-2025-3627 is an information disclosure vulnerability that allows users to access sensitive information.
CVE-2025-3627 was reported in early 2025.