Description
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.
Problem types
Use of GET Request Method With Sensitive Query Strings
Product status
4.5.0 (semver) before 4.5.4
4.4.0 (semver) before 4.4.8
4.3.0 (semver) before 4.3.12
4.1.0 (semver) before 4.1.18
Timeline
| 2025-04-15: | Reported to Red Hat. |
| 2025-04-22: | Made public. |
Credits
Red Hat would like to thank Simon Reinhart for reporting this issue.
References
git.moodle.org/....git&a=search&h=HEAD&st=commit&s=MDL-65356
access.redhat.com/security/cve/CVE-2025-3637
bugzilla.redhat.com/show_bug.cgi?id=2359727 (RHBZ#2359727)