« Volver al listado

CVE-2025-32045

Estado: AnalizadaMedia (5.3)—

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32045",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32045",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-25T15:37:20.319583Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "patrick@puiterwijk.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "patrick@puiterwijk.org",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "4.5.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.4.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.3.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.1.17",
              "versionType": "semver"
            }
          ],
          "packageName": "moodle",
          "collectionURL": "http://git.moodle.org/gw?p=moodle.git",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-04-25T15:15:36.307",
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2025-32045",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2356835",
      "tags": [
        "Issue Tracking"
      ],
      "source": "patrick@puiterwijk.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "patrick@puiterwijk.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una falla en Moodle donde las comprobaciones de capacidad insuficientes en ciertos informes de calificaciones permitían a usuarios sin los permisos necesarios acceder a calificaciones ocultas."
    }
  ],
  "lastModified": "2026-06-17T09:11:22.060",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "045AAB43-9136-4B4C-9D23-F94C05C5DBBD",
              "versionEndExcluding": "4.1.17"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75E13B63-E88F-4492-834E-39586A6970D3",
              "versionEndExcluding": "4.3.11",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8642DD73-001F-4B15-B197-8EAB19A755DB",
              "versionEndExcluding": "4.4.7",
              "versionStartIncluding": "4.4.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FD20A49-9A06-419E-AEDB-C794994A6C99",
              "versionEndExcluding": "4.5.3",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "patrick@puiterwijk.org"
}