CVE-2025-3627: Moodle makes some user data available before completing second factor with MFA enabled
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
References
Code Behaviors & Features
Detect and mitigate CVE-2025-3627 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →