Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12528 | A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA). |
Github GHSA |
GHSA-x45j-jq9q-gf3q | Moodle makes some user data available before completing second factor with MFA enabled |
Tue, 24 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Fri, 25 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA). | |
| Title | Moodle: partial data exposure in moodle before completing multi-factor authentication | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-04-25T16:01:15.301Z
Reserved: 2025-04-15T07:33:12.147Z
Link: CVE-2025-3627
Updated: 2025-04-25T15:43:19.564Z
Status : Analyzed
Published: 2025-04-25T15:15:36.927
Modified: 2025-06-24T16:17:23.420
Link: CVE-2025-3627
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:20Z
EUVD
Github GHSA