CVE-2025-3644: Moodle: ajax section delete does not respect course_can_delete_section()
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
Other sources
Additional checks were required to prevent users deleting course sections they did not have permission to modify.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed: 4.5.4, 4.4.8, 4.3.12 and 4.1.18
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3644?
CVE-2025-3644 is considered a high severity vulnerability due to its potential to allow unauthorized users to delete course sections.
How do I fix CVE-2025-3644?
To mitigate CVE-2025-3644, ensure that your Moodle installation is updated to version 4.5.4 or higher, which contains the necessary checks.
Which versions of Moodle are affected by CVE-2025-3644?
CVE-2025-3644 affects Moodle versions from 4.1 to 4.5.3 inclusive.
What types of users are impacted by CVE-2025-3644?
CVE-2025-3644 impacts users who may have inadequate permissions that could allow them to delete course sections.
Is CVE-2025-3644 being actively exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2025-3644, but it is recommended to apply the patch promptly.