BIT-moodle-2025-3634

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3634.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-moodle-2025-3634
Aliases
Published
2026-01-26T14:49:36Z
Modified
2026-09-08T08:48:15Z
Summary
Moodle: moodle allows course self-enrolment before completing mfa
Details

A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

Database specific
{
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.3.0
Fixed
4.3.12
Introduced
4.4.0
Fixed
4.4.8
Introduced
4.5.0
Fixed
4.5.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3634.json"