CVE-2025-3642
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 25, 2025
Updated: Apr 29, 2025
CWE ID 94
Summary
CVE-2025-3642 is a newly discovered vulnerability affecting Moodle, an open-source learning management system. The issue lies in the EQUELLA repository, which allows for remote code execution. This risk is significant because it can be exploited by unauthorized users, but by default, it is only accessible to teachers and managers on sites with the EQUELLA repository enabled. Successful exploitation could lead to serious data breaches or system compromise. It is essential that Moodle users update their systems to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.