CVE-2025-3637

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 598

Summary

CVE-2025-3637 is a newly identified vulnerability affecting the Moodle learning management system. It allows confidential information, which typically prevents cross-site request forgery (CSRF) attacks, to be accessible through the URL of certain pages within the mod_data module. Specifically, this issue is found on the edit and delete pages, increasing the risk of unauthorized modifications or access to sensitive data. This vulnerability poses a significant threat to organizations and educational institutions using Moodle, making it crucial to apply the necessary patches or updates as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share