#VU124623 Information disclosure in Moodle - CVE-2025-62400

 

#VU124623 Information disclosure in Moodle - CVE-2025-62400

Published: March 26, 2026 / Updated: March 26, 2026


Vulnerability identifier: #VU124623
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-62400
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Moodle
Software vendor:
moodle.org

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to insufficient capability checks. A remote user with access to create group calendar events can see hidden and separate groups in the list of groups to select for calendar events.


Remediation

Install updates from vendor's website.

External links