Description

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

INFO

Published Date :

2025-04-25T14:43:22.142Z

Last Modified :

2025-04-25T15:54:57.173Z

Source :

fedora
AFFECTED PRODUCTS

The following products are affected by CVE-2025-32044 vulnerability.

Vendors Products
Moodle
  • Moodle
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-32044.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact