Home

Description

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

PUBLISHED Reserved 2025-10-13 | Published 2025-10-23 | Updated 2025-10-23 | Assigner fedora




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

5.0.0 (semver) before 5.0.3
affected

4.5.0 (semver) before 4.5.7
affected

4.4.0 (semver) before 4.4.11
affected

4.1.0 (semver) before 4.1.21
affected

Timeline

2025-10-16:Reported to Red Hat.
2025-10-14:Made public.

Credits

Red Hat would like to thank Robert Toth for reporting this issue.

References

access.redhat.com/security/cve/CVE-2025-62400 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2404433 (RHBZ#2404433) issue-tracking

cve.org (CVE-2025-62400)

nvd.nist.gov (CVE-2025-62400)

Download JSON