Skip to main content

Moodle 3.9.25

Unsupported Moodle Version
This version of Moodle is no longer supported and will not receive fixes for security risks.
You are encouraged to upgrade to a supported version of Moodle.

Release date: 11 December 2023

Here is the full list of fixed issues in 3.9.25.

Security fixes

  • MSA-23-0044 - Authenticated remote code execution risk in logstore as manager
  • MSA-23-0045 - DOS risk in URL downloader
  • MSA-23-0046 - Authenticated remote code execution risk in course blocks
  • MSA-23-0047 - Logs and Live logs course reports did not respect activity group settings
  • MSA-23-0050 - Survey responses did not respect group settings
  • MSA-23-0051 - Badge recipients are available to all users
  • MSA-23-0052 - XSS risk when manually running a task in the admin UI