CVE-2025-62393: Moodle

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.

Affected products

  • Moodle Moodle: from 5.0.0, before 5.0.3 (fixed in 5.0.3)

Published 2025-10-23. Last modified 2026-06-17.