CVE-2025-62393: Moodle: course access permissions not properly checked in course_output_fragment_course_overview
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
Other sources
Insufficient handling of access control checks in the courseoutputfragmentcourseoverview() function allows information about restricted courses to be returned to users lacking proper permissions. An attacker with a valid Moodle account could exploit this to view metadata about inaccessible courses.
Versions affected: 5.0 to 5.0.2 Versions fixed: 5.0.3
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62393?
CVE-2025-62393 has been classified as a medium severity vulnerability due to unauthorized access risks.
How do I fix CVE-2025-62393?
To fix CVE-2025-62393, ensure that user access permissions are properly enforced within the course overview output function.
What types of information can be exposed by CVE-2025-62393?
CVE-2025-62393 can expose limited course details that unauthorized users should not have access to.
Which software is affected by CVE-2025-62393?
CVE-2025-62393 affects the Moodle platform.
Who should be concerned about CVE-2025-62393?
Administrators and users of Moodle should be concerned about CVE-2025-62393 due to potential unauthorized access issues.