Bug 2359690 (CVE-2025-3625) - CVE-2025-3625 moodle: User DoS and Name Disclosure via IDOR in Moodle MFA Email Factor Revoke Action
Summary: CVE-2025-3625 moodle: User DoS and Name Disclosure via IDOR in Moodle MFA Ema...
Keywords:
Status: NEW
Alias: CVE-2025-3625
Deadline: 2025-04-22
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2361791 2361792
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-04-15 07:20 UTC by OSIDB Bzimport
Modified: 2025-04-22 22:21 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-04-15 07:20:55 UTC
A missing check in the Multi-Factor Authentication (MFA) email factor's revoke/cancel action could allow an attacker to revoke a user's only available second authentication factor. This could prevent the user from successfully logging in (denial of service), and also disclose their name in the process via an Insecure Direct Object Reference (IDOR) vulnerability.

Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, and 4.3 to 4.3.11
Versions fixed: 4.5.4, 4.4.8, and 4.3.12


Note You need to log in before you can comment on or make changes to this bug.