A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
2025-04-25T15:15:36.927
2025-06-24T16:17:23.420
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | < 4.3.12 | Yes |
| Application | moodle | moodle | < 4.4.8 | Yes |
| Application | moodle | moodle | < 4.5.4 | Yes |