{"id":"GHSA-69m9-rprc-2x7g","summary":"Moodle reveals student identities through assignment submissions search on anonymous submissions","details":"A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.","aliases":["BIT-moodle-2025-3628","CVE-2025-3628"],"modified":"2026-01-26T17:41:08.900698Z","published":"2025-04-25T15:31:22Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-25T16:35:47Z","nvd_published_at":"2025-04-25T15:15:37Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3628"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/5c703f7b4944dd0cc940ca20adfd91e6a2d98a66"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-3628"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2359706"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=467595"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.5.0-beta"},{"fixed":"4.5.4"}]}],"versions":["v4.5.0","v4.5.0-beta","v4.5.0-rc1","v4.5.0-rc2","v4.5.1","v4.5.2","v4.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-69m9-rprc-2x7g/GHSA-69m9-rprc-2x7g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}