CVE-2025-62395
MEDIUMMoodle < 4.1.21 - Improper Access Control
Title source: ruleDescription
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
Scores
CVSS v3
4.3
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-284
Status
published
Affected Products (1)
moodle/moodle
< 4.1.21
Timeline
Published
Oct 23, 2025
Tracked Since
Feb 18, 2026