CVE-2025-3635

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 352

Summary

CVE-2025-3635 is a recently identified vulnerability in Moodle, an popular e-learning platform. The issue stems from insufficient protection against Cross-Site Request Forgery (CSRF) attacks. As a result, unauthenticated users can manipulate the system and replicate existing tours in the platform. This vulnerability poses a significant risk to Moodle installations, as it allows attackers to bypass authentication requirements and potentially gain unauthorized access to sensitive information. System administrators are advised to apply the necessary patches or updates to mitigate this issue promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share