CVE-2025-3637
CVSS 3.1 Score 3.1 of 10 (low)
Details
Summary
CVE-2025-3637 is a newly identified vulnerability affecting the Moodle learning management system. It allows confidential information, which typically prevents cross-site request forgery (CSRF) attacks, to be accessible through the URL of certain pages within the mod_data module. Specifically, this issue is found on the edit and delete pages, increasing the risk of unauthorized modifications or access to sensitive data. This vulnerability poses a significant threat to organizations and educational institutions using Moodle, making it crucial to apply the necessary patches or updates as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.