
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67847 is a code injection vulnerability in Moodle's restore interface that allows an authenticated attacker with access to that interface to trigger server-side execution of arbitrary code. The flaw stems from insufficient validation of restore input, which leads to unintended interpretation by core restore routines. It was published on January 23, 2026, and affects Moodle versions prior to 4.1.22, 4.4.0–4.4.11, 4.5.0–4.5.7, 5.0.0–5.0.3, and 5.1.0 (beta). The CVSS v3.1 base score is 8.8 (High), assigned by the Fedora Project (Github Advisory, Red Hat Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). When a user with access to Moodle's restore interface submits a crafted restore package or input, the core restore routines fail to adequately validate or sanitize the supplied data, causing it to be interpreted and executed as code on the server. The attack is network-accessible, requires only low privileges (access to the restore interface), and no user interaction beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (Github Advisory, Red Hat Advisory).
Successful exploitation results in full compromise of the Moodle application, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code on the server with the privileges of the Moodle application process, potentially enabling unauthorized access to all course data, user credentials, and sensitive institutional information stored in Moodle. This could also serve as a foothold for lateral movement within the hosting environment (Github Advisory, Red Hat Advisory).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.03% (9th percentile), indicating a currently low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (plugin 297398) and Qualys (detection 530893) (Github Advisory, Tenable Nessus).
/admin/index.php..mbz) or restore input that embeds code injection payloads targeting the insufficient validation in core restore routines.Course > Restore) and upload or submit the malicious restore package.moodledata/ with executable content./backup/restore*) with anomalous or oversized POST bodies; PHP error logs showing unexpected code evaluation or eval() calls during restore processing.bash, curl, wget, or python following a restore action; unexpected cron jobs or scheduled tasks created under the web server user account.Moodle has released patched versions addressing this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to the appropriate patched release as the primary remediation. As interim workarounds, restrict access to the restore interface to only highly trusted administrators, implement additional monitoring of restore activities for suspicious input patterns, and consider disabling the restore functionality if it is not actively required (Github Advisory, Moodle Forum).
The vulnerability received coverage from security aggregators and community feeds including The Hacker Wire, Bluesky CVE feeds, and INCIBE-CERT, reflecting standard community awareness for a high-severity Moodle flaw. No notable independent researcher commentary or significant vendor statements beyond the advisory itself have been identified. Qualys published detection information in their February 2026 application security detections roundup (Qualys Detections).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."