CVE-2025-3634

MEDIUM

Moodle 4.3.0-4.3.11 - Improper Authentication via Course Enrollment Bypass

Title source: llm
STIX 2.1

Description

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-3634
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2359707

Scores

CVSS v3 4.3
EPSS 0.0032
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
moodle/moodle 4.3.0 - 4.3.12
moodle/moodle 4.3.0-beta - 4.3.12Packagist
Published Apr 25, 2025
Tracked Since Feb 18, 2026