Description
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.
Problem types
Exposure of Information Through Directory Listing
Product status
5.0.0 (semver) before 5.0.3
4.5.0 (semver) before 4.5.7
Timeline
| 2025-10-16: | Reported to Red Hat. |
| 2025-10-14: | Made public. |
Credits
Red Hat would like to thank Yedidia Klein for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-62396
bugzilla.redhat.com/show_bug.cgi?id=2404429 (RHBZ#2404429)