CVE-2025-3637
25.04.2025, 15:15
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 4.3.12 |
moodle | moodle | 4.4.0 ≤ 𝑥 < 4.4.8 |
moodle | moodle | 4.5.0 ≤ 𝑥 < 4.5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration