Cross-Site Request Forgery Exposure in Moodle's Mod_Data Module
CVE-2025-3637
Currently unrated
What is CVE-2025-3637?
A security flaw was identified in Moodle that allows confidential information meant to prevent CSRF attacks to be leaked through publicly accessible URLs. This vulnerability is specifically present in the edit and delete pages of the mod_data module, affecting the integrity and security of sensitive user data. Organizations using affected versions of Moodle should take immediate action to implement the necessary patches to mitigate this issue.