CVE-2025-3640
25.04.2025, 15:15
A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 4.1.18 |
moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.12 |
moodle | moodle | 4.4.0 ≤ 𝑥 < 4.4.8 |
moodle | moodle | 4.5.0 ≤ 𝑥 < 4.5.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration