
We found results for “”
CVE-2025-3636
Good to know:

Date: April 25, 2025
A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Authorization Bypass Through User-Controlled Key
CWE-639Top Fix

Upgrade Version
Upgrade to version moodle/moodle - v4.3.12;moodle/moodle - v4.4.8;moodle/moodle - v4.5.4;moodle/moodle - v4.1.18
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |