CVE-2025-62393
Moodle: course access permissions not properly checked in course_output_fragment_course_overview
4.3
MEDIUM
CVSS 3.1
EPSS 0.05%
Description
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
How to fix CVE-2025-62393
To remediate CVE-2025-62393, upgrade the affected package to a fixed version below.
- —upgrade to 5.0.3 or later
- —upgrade to 5.0.3 or later
Is CVE-2025-62393 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 5.0.0, < 5.0.3
- >= 5.0.0-beta, < 5.0.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |