Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
4.5.0 (semver) before 4.5.4
affected
4.4.0 (semver) before 4.4.8
affected
4.3.0 (semver) before 4.3.12
affected
4.1.0 (semver) before 4.1.18
affected
Description
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
Problem types
Product status
4.5.0 (semver) before 4.5.4
4.4.0 (semver) before 4.4.8
4.3.0 (semver) before 4.3.12
4.1.0 (semver) before 4.1.18
Timeline
| 2025-04-15: | Reported to Red Hat. |
| 2025-04-22: | Made public. |
Credits
Red Hat would like to thank Paul Holden for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-3647
bugzilla.redhat.com/show_bug.cgi?id=2359762 (RHBZ#2359762)
moodle.org/mod/forum/discuss.php?d=467607