Sensitive Data Exposure in Moodle by Users without Authentication
CVE-2025-32044
Currently unrated
What is CVE-2025-32044?
A vulnerability in the Moodle Learning Platform allows unauthenticated users to access sensitive user information, including names, contact details, and hashed passwords. This issue arises from specific API calls returning stack traces on certain configurations. Sites running with 'zend.exception_ignore_args = 1' in the php.ini file are safeguarded from this exposure. It is crucial for administrators to review their settings to ensure their platforms remain secure.