Sensitive Data Exposure in Moodle by Users without Authentication
CVE-2025-32044

Currently unrated

Key Information:

Vendor
Moodle
Status
Vendor
CVE Published:
25 April 2025

Summary

A vulnerability in the Moodle Learning Platform allows unauthenticated users to access sensitive user information, including names, contact details, and hashed passwords. This issue arises from specific API calls returning stack traces on certain configurations. Sites running with 'zend.exception_ignore_args = 1' in the php.ini file are safeguarded from this exposure. It is crucial for administrators to review their settings to ensure their platforms remain secure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Lucas Alonso for reporting this issue.
.