CVE-2025-3628: Moodle: moodle assignment submission search leaks anonymous student identities
A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.
Other sources
Additional capability checks were required to prevent teachers from being able to identify a user's anonymous assignment submissions via the submissions search.
Versions affected: 4.5 to 4.5.3 Versions fixed: 4.5.4
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3628?
CVE-2025-3628 has been rated as a high severity vulnerability due to its potential to expose student identities.
How do I fix CVE-2025-3628?
To fix CVE-2025-3628, update Moodle to version 4.5.4 or later.
Which versions of Moodle are affected by CVE-2025-3628?
Moodle versions from 4.5.0-beta to 4.5.3 are affected by CVE-2025-3628.
What kind of vulnerability is CVE-2025-3628?
CVE-2025-3628 is a data exposure vulnerability that allows de-anonymization of anonymous assignment submissions.
What are the risks associated with CVE-2025-3628?
The risks include unauthorized exposure of student identities, which can compromise privacy and trust in the platform.