CVE-2025-3641: Moodle: authenticated remote code execution risk in the moodle lms dropbox repository
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
Other sources
A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default this was only available to teachers and managers, on sites with the Dropbox repository enabled.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed: 4.5.4, 4.4.8, 4.3.12 and 4.1.18
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3641?
CVE-2025-3641 is classified as a high severity vulnerability due to the risk of remote code execution.
How do I fix CVE-2025-3641?
To mitigate CVE-2025-3641, upgrade to the latest version of Moodle that addresses this vulnerability.
Which versions of Moodle are affected by CVE-2025-3641?
CVE-2025-3641 affects Moodle versions from 4.1 to 4.5.3 inclusive.
What type of vulnerability is CVE-2025-3641?
CVE-2025-3641 is a remote code execution vulnerability found in the Moodle LMS Dropbox repository.
Who is at risk from CVE-2025-3641?
Users with managed access to the Dropbox repository in Moodle are at risk of exploitation from CVE-2025-3641.