CVE-2025-62397
Moodle: router produces json instead of 404 error for invalid course id
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
moodleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →