First published: Tue Apr 15 2025(Updated: )
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | >=4.5<=4.5.3>=4.4<=4.4.7>=4.3<=4.3.11>=4.1<=4.1.17 | |
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
composer/moodle/moodle | <4.1.18 | 4.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3644 is considered a high severity vulnerability due to its potential to allow unauthorized users to delete course sections.
To mitigate CVE-2025-3644, ensure that your Moodle installation is updated to version 4.5.4 or higher, which contains the necessary checks.
CVE-2025-3644 affects Moodle versions from 4.1 to 4.5.3 inclusive.
CVE-2025-3644 impacts users who may have inadequate permissions that could allow them to delete course sections.
As of now, there are no confirmed reports of active exploitation for CVE-2025-3644, but it is recommended to apply the patch promptly.