Moderate severityOSV Advisory· Published Oct 23, 2025· Updated Oct 23, 2025
Moodle: course access permissions not properly checked in course_output_fragment_course_overview
CVE-2025-62393
Description
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 5.0.0-beta, < 5.0.3 | 5.0.3 |
Affected products
3- osv-coords2 versions
>= 5.0.0, < 5.0.3+ 1 more
- (no CPE)range: >= 5.0.0, < 5.0.3
- (no CPE)range: >= 5.0.0-beta, < 5.0.3
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rjcm-7v2p-9265ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-62393ghsaADVISORY
- access.redhat.com/security/cve/CVE-2025-62393ghsavdb-entryx_refsource_REDHATWEB
- bugzilla.redhat.com/show_bug.cgighsaissue-trackingx_refsource_REDHATWEB
- github.com/moodle/moodle/commit/fc69b4744ba0132cc3093fd81940be15bc293835ghsaWEB
- moodle.org/mod/forum/discuss.phpghsaWEB
News mentions
0No linked articles in our index yet.