Description
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
Problem types
Product status
4.5.0 (semver) before 4.5.4
4.4.0 (semver) before 4.4.8
4.3.0 (semver) before 4.3.12
Timeline
| 2025-04-15: | Reported to Red Hat. |
| 2025-04-22: | Made public. |
Credits
Red Hat would like to thank Guillaume Barat for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-3634
bugzilla.redhat.com/show_bug.cgi?id=2359707 (RHBZ#2359707)