Bug 2359690 (CVE-2025-3625)

Summary: CVE-2025-3625 moodle: User DoS and Name Disclosure via IDOR in Moodle MFA Email Factor Revoke Action
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2361791, 2361792    
Bug Blocks:    
Deadline: 2025-04-22   

Description OSIDB Bzimport 2025-04-15 07:20:55 UTC
A missing check in the Multi-Factor Authentication (MFA) email factor's revoke/cancel action could allow an attacker to revoke a user's only available second authentication factor. This could prevent the user from successfully logging in (denial of service), and also disclose their name in the process via an Insecure Direct Object Reference (IDOR) vulnerability.

Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, and 4.3 to 4.3.11
Versions fixed: 4.5.4, 4.4.8, and 4.3.12