Sensitive Data Exposure in Moodle by Users without Authentication
CVE-2025-32044

Currently unrated

Key Information:

Vendor

Moodle

Status
Vendor
CVE Published:
25 April 2025

What is CVE-2025-32044?

A vulnerability in the Moodle Learning Platform allows unauthenticated users to access sensitive user information, including names, contact details, and hashed passwords. This issue arises from specific API calls returning stack traces on certain configurations. Sites running with 'zend.exception_ignore_args = 1' in the php.ini file are safeguarded from this exposure. It is crucial for administrators to review their settings to ensure their platforms remain secure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Lucas Alonso for reporting this issue.
.