Vulnerability Details
Basic Information
| Title | Moodle allows unauthenticated REST API user data exposure |
|---|---|
| Type | github |
| Published | 2025-04-25T15:31:22 |
| Last Seen | 2025-04-25T16:38:13 |
| CVSS Score | 7.5 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-32044 |
|---|---|
| CWE | CWE-200 |
| Bulletin Family | software |
Description
A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites where PHP…
Impact Assessment
| Base Score | 7.5 |
|---|---|
| Severity | HIGH |