CVE-2025-32044 HIGH

CVE-2025-32044: Moodle: unauthenticated rest api user data exposure

Weakness CWE-200 · Info exposure
Published April 25, 2025
Last update April 25, 2025

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

Key dates

02Disclosure timeline

April 25, 2025 CVE published
April 25, 2025 Record updated