CVE-2025-32044

HIGH

Moodle 4.5.0-4.5.2 - Unauthenticated Exposure of Sensitive User Data via API Stack Traces

Title source: llm
STIX 2.1

Description

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-32044
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2356829

Scores

CVSS v3 7.5
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
moodle/moodle 4.5.0 - 4.5.3
moodle/moodle 4.5.0-beta - 4.5.3Packagist
Published Apr 25, 2025
Tracked Since Feb 18, 2026