← back
CVE-2025-62393

Moodle: course access permissions not properly checked in course_output_fragment_course_overview

CVSS 4.3 MEDIUMEPSS 0.2%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →