Vulnerability Description
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | >= 4.1.0, < 4.1.21 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2025-62395Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2404428Issue TrackingThird Party Advisory
FAQ
What is CVE-2025-62395?
CVE-2025-62395 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
How severe is CVE-2025-62395?
CVE-2025-62395 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62395?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.