Sensitive Data Exposure in Moodle by Users without Authentication
CVE-2025-32044
Currently unrated
Summary
A vulnerability in the Moodle Learning Platform allows unauthenticated users to access sensitive user information, including names, contact details, and hashed passwords. This issue arises from specific API calls returning stack traces on certain configurations. Sites running with 'zend.exception_ignore_args = 1' in the php.ini file are safeguarded from this exposure. It is crucial for administrators to review their settings to ensure their platforms remain secure.
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Lucas Alonso for reporting this issue.