First published: Tue Apr 15 2025(Updated: )
A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=4.5<=4.5.3>=4.4<=4.4.7>=4.3<=4.3.11>=4.1<=4.1.17 | |
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
composer/moodle/moodle | <4.1.18 | 4.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3636 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive information.
To fix CVE-2025-3636, upgrade your Moodle installation to version 4.5.4, 4.4.8, 4.3.12, or 4.1.18.
CVE-2025-3636 affects Moodle versions 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, and 4.1 to 4.1.17.
CVE-2025-3636 is a flaw related to insufficient capability checks that allow unauthorized access to RSS feeds.
Users of the affected Moodle versions may be impacted as the vulnerability exposes unauthorized RSS feeds.