{"id":"GHSA-x45j-jq9q-gf3q","summary":"Moodle makes some user data available before completing second factor with MFA enabled","details":"A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).","aliases":["BIT-moodle-2025-3627","CVE-2025-3627"],"modified":"2026-01-26T17:41:08.713596Z","published":"2025-04-25T15:31:22Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-25T16:35:19Z","nvd_published_at":"2025-04-25T15:15:36Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3627"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-3627"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2359692"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://github.com/search?q=repo%3Amoodle%2Fmoodle+MDL-84351&type=commits"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=467594"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0-beta"},{"fixed":"4.3.12"}]}],"versions":["v4.3.0","v4.3.0-beta","v4.3.0-rc1","v4.3.0-rc2","v4.3.1","v4.3.10","v4.3.11","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-x45j-jq9q-gf3q/GHSA-x45j-jq9q-gf3q.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0-beta"},{"fixed":"4.4.8"}]}],"versions":["v4.4.0","v4.4.0-beta","v4.4.0-rc1","v4.4.0-rc2","v4.4.1","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.4.6","v4.4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-x45j-jq9q-gf3q/GHSA-x45j-jq9q-gf3q.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.5.0-beta"},{"fixed":"4.5.4"}]}],"versions":["v4.5.0","v4.5.0-beta","v4.5.0-rc1","v4.5.0-rc2","v4.5.1","v4.5.2","v4.5.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-x45j-jq9q-gf3q/GHSA-x45j-jq9q-gf3q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}