
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67855 is a reflected Cross-Site Scripting (XSS) vulnerability in Moodle's policy tool return URL parameter. A remote, unauthenticated attacker can exploit this flaw by crafting a malicious link that, when clicked by a victim, executes arbitrary JavaScript in the user's browser. The vulnerability affects Moodle versions 4.1.x before 4.1.22, 4.4.x before 4.4.11, 4.5.x before 4.5.8, and 5.0.x before 5.0.4, as well as 5.1.0. It was reported on December 19, 2025 and published to NVD on February 3, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Bugzilla, Feedly).
The root cause is insufficient sanitization of URL parameters in Moodle's policy tool before they are reflected back in the HTTP response, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An attacker crafts a specially formed URL targeting the policy tool's return URL parameter and tricks a victim into clicking it; the unsanitized input is then rendered in the browser, executing the injected script in the context of the victim's session. Exploitation requires no authentication and no special privileges, but does require user interaction (the victim must follow the malicious link) (Red Hat Bugzilla, Feedly).
Successful exploitation allows an attacker to execute arbitrary client-side scripts within the victim's browser session, potentially leading to session token theft, credential harvesting, phishing overlays, or unauthorized actions performed on behalf of the victim. The scope is changed (cross-origin impact possible), with low confidentiality and low integrity impact, and no direct availability impact. While the individual impact per exploitation is limited, the vulnerability could be chained with other weaknesses to escalate privileges or facilitate account takeover in Moodle deployments (Red Hat Bugzilla, Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-67855 as of the available data. The EPSS score is approximately 0.049%, indicating a low probability of exploitation in the near term. The vulnerability is detected by Nessus plugin 297912 and has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, Tenable Nessus).
returnurl or equivalent URL parameter (e.g., /admin/tool/policy/index.php?returnurl=...).https://target-moodle.example.com/admin/tool/policy/index.php?returnurl=javascript:alert(document.cookie) or an encoded equivalent that bypasses basic filters./admin/tool/policy/) containing URL-encoded JavaScript payloads or unusual characters (<, >, script, javascript:, onerror=, etc.) in the returnurl or similar parameters.Moodle has addressed this vulnerability in versions 4.1.22, 4.4.11, 4.5.8, and 5.0.4. Administrators should upgrade to one of these patched releases as the primary remediation. As a temporary workaround, restricting access to the policy tool to trusted networks or authenticated administrators only can reduce exposure. Additionally, deploying a Web Application Firewall (WAF) with XSS filtering rules can help mitigate exploitation attempts while patching is underway (Moodle Forum, Red Hat Bugzilla).
The vulnerability was reported through Red Hat's security response process and tracked in Red Hat Bugzilla, indicating coordination between the Moodle community and downstream distributors. No significant public researcher commentary, social media discussion, or major media coverage has been identified for this CVE beyond standard vulnerability database entries and automated aggregator posts (Red Hat Bugzilla, Feedly).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."