A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Vendors & Products |
Moodle
Moodle moodle |
Thu, 23 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 23 Oct 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details. | |
| Title | Moodle: course access permissions not properly checked in course_output_fragment_course_overview | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published: 2025-10-23T11:28:25.023Z
Updated: 2025-10-23T14:18:34.564Z
Reserved: 2025-10-13T10:12:30.924Z
Link: CVE-2025-62393
Updated: 2025-10-23T14:18:29.276Z
Status : Awaiting Analysis
Published: 2025-10-23T12:15:31.073
Modified: 2025-10-27T13:20:33.350
Link: CVE-2025-62393
No data.