← back
CVE-2025-3634

Moodle: moodle allows course self-enrolment before completing mfa

CVSS 4.3 MEDIUMEPSS 0.2%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →