Sensitive Information Exposure in Moodle by Moodle Pty Ltd
CVE-2025-3627
Currently unrated
What is CVE-2025-3627?
A vulnerability exists in the Moodle platform that potentially allows users to gain unauthorized access to sensitive information of other students prior to the successful verification of their identity through two-factor authentication (2FA). This flaw could lead to significant privacy violations, as unverified users may exploit it to view confidential data. Organizations using Moodle should apply recommended security patches to mitigate risks associated with this vulnerability.