CVE-2025-3634
Moodle: moodle allows course self-enrolment before completing mfa
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
25 abr 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
moodle¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →