CVE-2025-62396

MEDIUM

Moodle - Info Disclosure

Title source: llm

Description

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 15.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-548
Status published

Affected Products (2)

moodle/moodle < 4.5.7
moodle/moodle < 5.0.3Packagist

Timeline

Published Oct 23, 2025
Tracked Since Feb 18, 2026