Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. moodle/moodle
  4. ›
  5. CVE-2025-62393

CVE-2025-62393: Moodle course access permissions are not properly checked in course_output_fragment_course_overview

October 23, 2025 (updated October 24, 2025)

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.

References

  • access.redhat.com/security/cve/CVE-2025-62393
  • bugzilla.redhat.com/show_bug.cgi?id=2404426
  • github.com/advisories/GHSA-rjcm-7v2p-9265
  • github.com/moodle/moodle
  • github.com/moodle/moodle/commit/fc69b4744ba0132cc3093fd81940be15bc293835
  • moodle.org/mod/forum/discuss.php?d=470381
  • nvd.nist.gov/vuln/detail/CVE-2025-62393

Code Behaviors & Features

Detect and mitigate CVE-2025-62393 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.0.0-beta before 5.0.3

Fixed versions

  • 5.0.3

Solution

Upgrade to version 5.0.3 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-284: Improper Access Control

Source file

packagist/moodle/moodle/CVE-2025-62393.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 09 Nov 2025 12:19:16 +0000.