The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 14 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
Title Moodle: router produces json instead of 404 error for invalid course id
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-10-23T14:12:29.386Z

Reserved: 2025-10-13T10:12:30.925Z

Link: CVE-2025-62397

cve-icon Vulnrichment

Updated: 2025-10-23T14:12:25.820Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-23T12:15:32.270

Modified: 2025-11-14T19:19:30.210

Link: CVE-2025-62397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-24T10:17:04Z