CVE-2025-62400

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-62400
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62400.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62400
Aliases
Downstream
Published
2025-10-23T12:15:32.757Z
Modified
2025-11-20T12:40:46.332478Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

References

Affected packages

Git / github.com/moodle/moodle

Affected ranges

Type
GIT
Repo
https://github.com/moodle/moodle
Events

Affected versions

v4.*

v4.1.0
v4.1.1
v4.1.10
v4.1.11
v4.1.12
v4.1.13
v4.1.14
v4.1.15
v4.1.16
v4.1.17
v4.1.18
v4.1.19
v4.1.2
v4.1.20
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.1.7
v4.1.8
v4.1.9