A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2025-3625 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2359690 | issue tracking |