Bug 2404426 (CVE-2025-62393)

Summary: CVE-2025-62393 moodle: Course access permissions not properly checked in course_output_fragment_course_overview
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2404463, 2404464    
Bug Blocks:    

Description OSIDB Bzimport 2025-10-16 14:12:37 UTC
Insufficient handling of access control checks in the course_output_fragment_course_overview() function allows information about restricted courses to be returned to users lacking proper permissions. An attacker with a valid Moodle account could exploit this to view metadata about inaccessible courses.

Versions affected: 5.0 to 5.0.2
Versions fixed: 5.0.3