← back
CVE-2025-62401

Moodle: possible to bypass timer in timed assignments

CVSS 5.4 MEDIUMEPSS 0.2%CWE-285
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected products
moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →