Moodle, Information Disclosure, CVE-2025-XXXX (Moderate)

Listen to this Post

The vulnerability exists within the `r.php` router script responsible for handling external requests. When the application encounters a specific error condition, it attempts to display an error message. However, due to insufficient validation of the HTTP request context, if certain HTTP headers are missing or malformed, the error handling routine fails to properly catch and process the exception. This failure causes the script to default to a system-level error reporting mode. Instead of showing a generic error page to the user, this mode inadvertently outputs a detailed directory listing of the Moodle installation’s internal web root. The disclosure reveals the full server path structure, potentially exposing sensitive directory names, configuration file paths, and other internal information that could be leveraged for further attacks. The issue is triggered by a malformed request that bypasses the normal application flow and triggers an unhandled exception.
Platform: Moodle
Version: >=5.0.0-beta
Vulnerability: Information Disclosure
Severity: Moderate

date: 2025-10-23

Prediction: 2025-11-06

What Undercode Say:

curl -H "X-Forwarded-Host:" http://moodle-site/r.php
// Example error path exposure
echo $SERVER['DOCUMENT_ROOT'];

How Exploit:

Craft HTTP requests.

Omit specific headers.

Trigger error handler.

Leak directory paths.

Protection from this CVE

Update to patched versions.

Configure proper error reporting.

Validate all HTTP headers.

Restrict server path disclosure.

Impact:

Internal path disclosure.

Information leakage.

Aiding targeted attacks.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top