VulnerabilityAnalyzed
CVE-2025-62393
This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
MEDIUM 4.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- moodle/moodle
- Source
- patrick@puiterwijk.org
References
- https://access.redhat.com/security/cve/CVE-2025-62393Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2404426Issue Tracking, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=470381Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.