PT-2025-17915 · Moodle+2 · Moodle+2

Khikhi

·

Published

2025-04-22

·

Updated

2026-01-26

·

CVE-2025-3640

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw was found in the software, where insufficient capability checks allowed a user enrolled in a course to access certain details of other users they did not have permission to access, such as the full name and profile image URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
BDU:2025-05103
BIT-MOODLE-2025-3640
CVE-2025-3640
GHSA-6G5X-H5X7-Q4MQ

Affected Products

Alt Linux
Moodle
Red Os