CVE-2025-67847: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-67847 is a code injection vulnerability in Moodle's restore interface that allows an authenticated attacker with access to that interface to trigger server-side execution of arbitrary code. The flaw stems from insufficient validation of restore input, which leads to unintended interpretation by core restore routines. It was published on January 23, 2026, and affects Moodle versions prior to 4.1.22, 4.4.0–4.4.11, 4.5.0–4.5.7, 5.0.0–5.0.3, and 5.1.0 (beta). The CVSS v3.1 base score is 8.8 (High), assigned by the Fedora Project (Github Advisory, Red Hat Advisory).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). When a user with access to Moodle's restore interface submits a crafted restore package or input, the core restore routines fail to adequately validate or sanitize the supplied data, causing it to be interpreted and executed as code on the server. The attack is network-accessible, requires only low privileges (access to the restore interface), and no user interaction beyond the attacker's own actions. No public proof-of-concept code has been identified at this time (Github Advisory, Red Hat Advisory).

Impact

Successful exploitation results in full compromise of the Moodle application, with high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code on the server with the privileges of the Moodle application process, potentially enabling unauthorized access to all course data, user credentials, and sensitive institutional information stored in Moodle. This could also serve as a foothold for lateral movement within the hosting environment (Github Advisory, Red Hat Advisory).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.03% (9th percentile), indicating a currently low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (plugin 297398) and Qualys (detection 530893) (Github Advisory, Tenable Nessus).

Exploitation steps

  1. Reconnaissance: Identify Moodle instances running vulnerable versions (< 4.1.22, 4.4.0–4.4.11, 4.5.0–4.5.7, 5.0.0–5.0.3, or 5.1.0) using Shodan, Censys, or similar tools. Check the Moodle version via the login page footer or /admin/index.php.
  2. Obtain authenticated access: Acquire credentials for an account with access to the restore interface — this may be a teacher, course creator, or administrator role depending on site configuration.
  3. Craft malicious restore input: Prepare a specially crafted Moodle backup file (.mbz) or restore input that embeds code injection payloads targeting the insufficient validation in core restore routines.
  4. Trigger the restore: Navigate to the course restore interface (e.g., Course > Restore) and upload or submit the malicious restore package.
  5. Achieve code execution: The core restore routines process the malicious input without adequate validation, causing server-side execution of the injected code with the privileges of the Moodle web application process, enabling reverse shell establishment, data exfiltration, or further system compromise (Github Advisory).

Indicators of compromise

  • Network: Unusual outbound connections from the Moodle web server process to external IPs following restore operations; unexpected DNS lookups from the web server host.
  • File System: Unexpected PHP files or web shells written to the Moodle data directory or web root following a restore operation; new or modified files in moodledata/ with executable content.
  • Logs: Moodle access logs showing restore interface requests (/backup/restore*) with anomalous or oversized POST bodies; PHP error logs showing unexpected code evaluation or eval() calls during restore processing.
  • Process: Unusual child processes spawned by the web server (e.g., Apache/Nginx/PHP-FPM) such as bash, curl, wget, or python following a restore action; unexpected cron jobs or scheduled tasks created under the web server user account.

Mitigation and workarounds

Moodle has released patched versions addressing this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to the appropriate patched release as the primary remediation. As interim workarounds, restrict access to the restore interface to only highly trusted administrators, implement additional monitoring of restore activities for suspicious input patterns, and consider disabling the restore functionality if it is not actively required (Github Advisory, Moodle Forum).

Community reactions

The vulnerability received coverage from security aggregators and community feeds including The Hacker Wire, Bluesky CVE feeds, and INCIBE-CERT, reflecting standard community awareness for a high-severity Moodle flaw. No notable independent researcher commentary or significant vendor statements beyond the advisory itself have been identified. Qualys published detection information in their February 2026 application security detections roundup (Qualys Detections).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

moodle

Unknown

xenial (esm-apps-legacy)

moodle

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management