Untriaged
Permalink
CVE-2025-62400
4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
Moodle: hidden group names visible to event creators
Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.
References
Affected products
moodle
- <5.0.3
- <4.1.21
- <4.5.7
- <4.4.11
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>