CVE-2025-3634
Moodle: moodle allows course self-enrolment before completing mfa
4.3
MEDIUM
CVSS 3.1
EPSS 0.15%
Description
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
How to fix CVE-2025-3634
To remediate CVE-2025-3634, upgrade the affected package to a fixed version below.
- —upgrade to 4.3.12 or later
- —upgrade to 4.3.12 or later
Is CVE-2025-3634 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 4.3.0, < 4.3.12, >= 4.4.0, < 4.4.8, >= 4.5.0, < 4.5.4
- >= 4.3.0-beta, < 4.3.12
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |