CVE-2025-3634

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

24 Jun 2025, 16:16

Type Values Removed Values Added
First Time Moodle
Moodle moodle
References () https://bugzilla.redhat.com/show_bug.cgi?id=2359707 - () https://bugzilla.redhat.com/show_bug.cgi?id=2359707 - Issue Tracking
References () https://access.redhat.com/security/cve/CVE-2025-3634 - () https://access.redhat.com/security/cve/CVE-2025-3634 - Third Party Advisory
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

25 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-25 14:15

Updated : 2025-06-24 16:16


NVD link : CVE-2025-3634

Mitre link : CVE-2025-3634


JSON object : View

Products Affected

moodle

  • moodle
CWE

No CWE.