Vulnerability Details
Basic Information
| Title | CVE-2025-32044 Moodle: unauthenticated rest api user data exposure |
|---|---|
| Type | cve |
| Published | 2025-04-25T14:43:22 |
| Last Seen | 2025-04-25T15:24:05 |
| CVSS Score | 7.5 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-32044 |
|---|---|
| CWE | CWE-200 |
| Bulletin Family | cve |
Description
A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP…
Impact Assessment
| Base Score | 7.5 |
|---|---|
| Severity | HIGH |