CVE-2025-67855: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-67855 is a reflected Cross-Site Scripting (XSS) vulnerability in Moodle's policy tool return URL parameter. A remote, unauthenticated attacker can exploit this flaw by crafting a malicious link that, when clicked by a victim, executes arbitrary JavaScript in the user's browser. The vulnerability affects Moodle versions 4.1.x before 4.1.22, 4.4.x before 4.4.11, 4.5.x before 4.5.8, and 5.0.x before 5.0.4, as well as 5.1.0. It was reported on December 19, 2025 and published to NVD on February 3, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Bugzilla, Feedly).

Technical details

The root cause is insufficient sanitization of URL parameters in Moodle's policy tool before they are reflected back in the HTTP response, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An attacker crafts a specially formed URL targeting the policy tool's return URL parameter and tricks a victim into clicking it; the unsanitized input is then rendered in the browser, executing the injected script in the context of the victim's session. Exploitation requires no authentication and no special privileges, but does require user interaction (the victim must follow the malicious link) (Red Hat Bugzilla, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary client-side scripts within the victim's browser session, potentially leading to session token theft, credential harvesting, phishing overlays, or unauthorized actions performed on behalf of the victim. The scope is changed (cross-origin impact possible), with low confidentiality and low integrity impact, and no direct availability impact. While the individual impact per exploitation is limited, the vulnerability could be chained with other weaknesses to escalate privileges or facilitate account takeover in Moodle deployments (Red Hat Bugzilla, Feedly).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-67855 as of the available data. The EPSS score is approximately 0.049%, indicating a low probability of exploitation in the near term. The vulnerability is detected by Nessus plugin 297912 and has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly, Tenable Nessus).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Moodle instances running affected versions (4.1.x < 4.1.22, 4.4.x < 4.4.11, 4.5.x < 4.5.8, 5.0.x < 5.0.4, or 5.1.0) using search engines, Shodan, or Censys.
  2. Identify the vulnerable endpoint: Locate the Moodle policy tool page that accepts a returnurl or equivalent URL parameter (e.g., /admin/tool/policy/index.php?returnurl=...).
  3. Craft malicious URL: Construct a URL with a JavaScript payload injected into the return URL parameter, such as: https://target-moodle.example.com/admin/tool/policy/index.php?returnurl=javascript:alert(document.cookie) or an encoded equivalent that bypasses basic filters.
  4. Deliver the payload: Send the crafted URL to a target user (e.g., a Moodle administrator or authenticated student) via phishing email, forum post, or other social engineering vector.
  5. Achieve objective: When the victim clicks the link and the page loads, the injected script executes in their browser session, enabling the attacker to steal session cookies, perform actions on behalf of the victim, or redirect to a phishing page (Red Hat Bugzilla, Feedly).

Indicators of compromise

  • Network: HTTP GET requests to Moodle policy tool endpoints (e.g., /admin/tool/policy/) containing URL-encoded JavaScript payloads or unusual characters (<, >, script, javascript:, onerror=, etc.) in the returnurl or similar parameters.
  • Logs: Web server access logs showing requests to policy tool pages with anomalous query strings; Moodle application logs recording unexpected redirects or parameter values containing script tags.
  • User Activity: Reports from users of unexpected browser pop-ups, redirects to unknown sites, or session anomalies after clicking links purportedly from the Moodle instance.
  • Browser/Client: Victim browsers making unexpected outbound requests to attacker-controlled domains shortly after visiting a Moodle policy page (Red Hat Bugzilla).

Mitigation and workarounds

Moodle has addressed this vulnerability in versions 4.1.22, 4.4.11, 4.5.8, and 5.0.4. Administrators should upgrade to one of these patched releases as the primary remediation. As a temporary workaround, restricting access to the policy tool to trusted networks or authenticated administrators only can reduce exposure. Additionally, deploying a Web Application Firewall (WAF) with XSS filtering rules can help mitigate exploitation attempts while patching is underway (Moodle Forum, Red Hat Bugzilla).

Community reactions

The vulnerability was reported through Red Hat's security response process and tracked in Red Hat Bugzilla, indicating coordination between the Moodle community and downstream distributors. No significant public researcher commentary, social media discussion, or major media coverage has been identified for this CVE beyond standard vulnerability database entries and automated aggregator posts (Red Hat Bugzilla, Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

moodle

Unknown

xenial (esm-apps-legacy)

moodle

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management