PT-2025-20639 · Moodle · Catalyst User Key Authentication Plugin

Cyber-Wo0Dy

·

Published

2025-05-10

·

Updated

2025-05-10

·

CVE-2025-4513

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Catalyst User Key Authentication Plugin version 20220819
Description A vulnerability was found in the Catalyst User Key Authentication Plugin on Moodle, affecting an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the return argument leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For Catalyst User Key Authentication Plugin version 20220819, as a temporary workaround, consider restricting access to the /auth/userkey/logout.php endpoint until a patch is available. Avoid using the return argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-4513

Affected Products

Catalyst User Key Authentication Plugin