Untriaged
Permalink
CVE-2025-62401
5.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): LOW
- Availability impact (A): LOW
Moodle: possible to bypass timer in timed assignments
An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.
References
Affected products
moodle
- <5.0.3
- <4.1.21
- <4.5.7
- <4.4.11
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>