First published: Tue Apr 15 2025(Updated: )
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=4.5<=4.5.3>=4.4<=4.4.7>=4.3<=4.3.11 | |
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3634 is categorized as a high-severity vulnerability due to its potential to allow unauthorized course enrollments.
To remediate CVE-2025-3634, upgrade to Moodle version 4.5.4, 4.4.8, or 4.3.12 depending on your current version.
CVE-2025-3634 affects Moodle versions 4.5.0 to 4.5.3, 4.4.0 to 4.4.7, and 4.3.0 to 4.3.11.
If exploited, CVE-2025-3634 allows students to enroll in courses without completing required verification processes, potentially compromising course integrity.
Yes, a patch is available in the form of updated versions: 4.5.4, 4.4.8, and 4.3.12 for Moodle.