CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-62400 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2404433 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

14 Nov 2025, 19:07

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://access.redhat.com/security/cve/CVE-2025-62400 - () https://access.redhat.com/security/cve/CVE-2025-62400 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2404433 - () https://bugzilla.redhat.com/show_bug.cgi?id=2404433 - Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
First Time Moodle moodle
Moodle

23 Oct 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-23 12:15

Updated : 2025-11-14 19:07


NVD link : CVE-2025-62400

Mitre link : CVE-2025-62400

CVE.ORG link : CVE-2025-62400


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo