CVE-2025-62395

MEDIUM

Moodle < 4.1.21 - Improper Access Control

Title source: rule

Description

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-284
Status published

Affected Products (1)

moodle/moodle < 4.1.21

Timeline

Published Oct 23, 2025
Tracked Since Feb 18, 2026