CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-62400 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2404433 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-23 12:15

Updated : 2025-11-14 19:07


NVD link : CVE-2025-62400

Mitre link : CVE-2025-62400

CVE.ORG link : CVE-2025-62400


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo