A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
History

Fri, 25 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
Title Moodle: moodle allows course self-enrolment before completing mfa
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2025-04-25T14:02:05.222Z

Updated: 2025-04-25T14:42:48.989Z

Reserved: 2025-04-15T09:52:09.173Z

Link: CVE-2025-3634

cve-icon Vulnrichment

Updated: 2025-04-25T14:24:00.284Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-25T14:15:22.917

Modified: 2025-04-29T13:52:28.490

Link: CVE-2025-3634

cve-icon Redhat

No data.