CVE-2025-3625
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- moodle/moodle
- Source
- patrick@puiterwijk.org
References
- https://access.redhat.com/security/cve/CVE-2025-3625Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2359690Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.