CVE-2025-62393
Moodle: course access permissions not properly checked in course_output_fragment_course_overview
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
moodleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →