The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
Title Moodle: router produces json instead of 404 error for invalid course id
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-10-23T14:12:29.386Z

Reserved: 2025-10-13T10:12:30.925Z

Link: CVE-2025-62397

cve-icon Vulnrichment

Updated: 2025-10-23T14:12:25.820Z

cve-icon NVD

Status : Received

Published: 2025-10-23T12:15:32.270

Modified: 2025-10-23T12:15:32.270

Link: CVE-2025-62397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.