CVE-2025-3647: Moodle: idor when accessing the cohorts report
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
Other sources
Additional checks were required to ensure users can only fetch cohort data they are intended to have access to.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed:4.5.4, 4.4.8, 4.3.12 and 4.1.18
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3647?
CVE-2025-3647 has been classified as a moderate severity vulnerability.
How do I fix CVE-2025-3647?
To address CVE-2025-3647, update your Moodle installation to version 4.5.4 or later, which includes the necessary access controls.
What versions of Moodle are affected by CVE-2025-3647?
CVE-2025-3647 affects Moodle versions from 0 up to 4.5.3, including multiple versions of 4.4, 4.3, and 4.1.
What type of vulnerability is CVE-2025-3647?
CVE-2025-3647 is an access control vulnerability that allows unauthorized access to cohort data.
Is there a workaround for CVE-2025-3647?
No formal workarounds have been published for CVE-2025-3647; upgrading to a patched version is recommended.