Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12524 | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages. |
Github GHSA |
GHSA-9vc3-vm42-fjhm | Moodle's mod_data edit/delete pages pass CSRF token in GET parameter |
Tue, 24 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Fri, 25 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages. | |
| Title | Moodle: csrf token exposure via url in moodle mod_data module | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-04-25T15:56:03.369Z
Reserved: 2025-04-15T11:19:07.842Z
Link: CVE-2025-3637
Updated: 2025-04-25T15:43:04.109Z
Status : Analyzed
Published: 2025-04-25T15:15:37.510
Modified: 2025-06-24T16:09:21.100
Link: CVE-2025-3637
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA