Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
4.5.0 (semver) before 4.5.4
affected
4.4.0 (semver) before 4.4.8
affected
4.3.0 (semver) before 4.3.12
affected
4.1.0 (semver) before 4.1.18
affected
Description
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
Problem types
Product status
4.5.0 (semver) before 4.5.4
4.4.0 (semver) before 4.4.8
4.3.0 (semver) before 4.3.12
4.1.0 (semver) before 4.1.18
Timeline
| 2025-04-15: | Reported to Red Hat. |
| 2025-04-22: | Made public. |
Credits
Red Hat would like to thank ostapbender for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-3645
bugzilla.redhat.com/show_bug.cgi?id=2359761 (RHBZ#2359761)
moodle.org/mod/forum/discuss.php?d=467606