First published: Fri Apr 25 2025(Updated: )
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=4.5.0-beta<4.5.4 | 4.5.4 |
composer/moodle/moodle | >=4.4.0-beta<4.4.8 | 4.4.8 |
composer/moodle/moodle | >=4.3.0-beta<4.3.12 | 4.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GHSA-x45j-jq9q-gf3q is classified as a moderate severity vulnerability.
To fix GHSA-x45j-jq9q-gf3q, upgrade Moodle to versions 4.5.4, 4.4.8, or 4.3.12 or later.
Users of Moodle versions prior to 4.5.4, 4.4.8, and 4.3.12 may be affected by GHSA-x45j-jq9q-gf3q.
GHSA-x45j-jq9q-gf3q allows some users to access sensitive information regarding other students.
GHSA-x45j-jq9q-gf3q is caused by improper handling of identity verification during the two-factor authentication process.