Information disclosure in Moodle - CVE-2025-62400
Published: March 26, 2026 / Updated: March 26, 2026
Vulnerability identifier: #VU124623
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62400
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to insufficient capability checks. A remote user with access to create group calendar events can see hidden and separate groups in the list of groups to select for calendar events.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2025-62400
Install updates from vendor's website.
Moodle - addressed in versions 4.1.21, 4.4.11, 4.5.7, 5.0.3
moodle - addressed in versions 4.4.11-1.fc41, 4.5.7-1.fc42, 5.0.3-1.fc43
moodle - addressed in versions 4.4.11-1.fc41, 4.5.7-1.fc42, 5.0.3-1.fc43