CVE-2025-3636: Moodle: idor in moodle rss block allows unauthorized access to rss feeds
A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.
Other sources
Inadequate permission checks exposed unauthorized RSS feeds to users.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions Versions fixed: 4.5.4, 4.4.8, 4.3.12 and 4.1.18
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3636?
CVE-2025-3636 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-3636?
To fix CVE-2025-3636, upgrade your Moodle installation to version 4.5.4, 4.4.8, 4.3.12, or 4.1.18.
Which versions of Moodle are affected by CVE-2025-3636?
CVE-2025-3636 affects Moodle versions 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, and 4.1 to 4.1.17.
What type of vulnerability is CVE-2025-3636?
CVE-2025-3636 is a flaw related to insufficient capability checks that allow unauthorized access to RSS feeds.
Who can be impacted by CVE-2025-3636?
Users of the affected Moodle versions may be impacted as the vulnerability exposes unauthorized RSS feeds.