A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
History

Fri, 25 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
Title Moodle: user dos and name disclosure via idor in moodle mfa email factor revoke action
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2025-04-25T14:42:39.887Z

Updated: 2025-04-25T16:01:25.670Z

Reserved: 2025-04-15T06:45:25.748Z

Link: CVE-2025-3625

cve-icon Vulnrichment

Updated: 2025-04-25T15:43:23.220Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-25T15:15:36.753

Modified: 2025-04-29T13:52:28.490

Link: CVE-2025-3625

cve-icon Redhat

No data.