CVE-2025-67857
PHP vulnerability analysis and mitigation

Overview

CVE-2025-67857 is an information disclosure vulnerability in Moodle, the open-source learning management system, where internal user identifiers are inadvertently exposed in URLs during anonymous assignment submissions. This flaw compromises the intended anonymity of submissions, allowing unauthorized viewers to identify students via their internal user IDs. Affected versions include Moodle < 4.1.22, >= 4.4.0-beta and < 4.4.12, >= 4.5.0-beta and < 4.5.8, >= 5.0.0-beta and < 5.0.4, and >= 5.1.0-beta and < 5.1.1. The vulnerability was reported in December 2025 and publicly disclosed on February 3, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) per the GitHub Advisory, or 5.3 (Medium) per NVD scoring (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), where Moodle's anonymous assignment submission workflow fails to strip or obfuscate internal user identifiers before embedding them in URLs (Github Advisory). An attacker or unauthorized viewer who can observe or access these URLs — for example, through browser history, server logs, or a shared link — can extract the internal Moodle user ID of the submitting student. Exploitation requires user interaction (e.g., a victim clicking a link or an observer viewing a URL), and no authentication is required to read the exposed identifier from the URL itself. Patches are available in the Moodle source repository via commits ac30e7e and c6cb8d9 (Github Advisory).

Impact

Successful exploitation results in a low-severity confidentiality breach: internal Moodle user IDs are exposed to unauthorized parties, undermining the anonymity guarantees of anonymous assignment submissions (Github Advisory). There is no impact on integrity or availability. While the exposed data is limited to internal user identifiers rather than full personal information, it could enable an adversary to correlate anonymous submissions with specific students, potentially violating privacy policies or academic integrity protections (Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Identify a target Moodle instance: Locate a Moodle deployment running a vulnerable version (< 4.1.22, < 4.4.12, < 4.5.8, < 5.0.4, or < 5.1.1) that has anonymous assignment submissions enabled.
  2. Obtain or observe a submission URL: Access or intercept a URL generated during an anonymous assignment submission — this could be through browser history, server access logs, network traffic observation, or by having a student share a link.
  3. Extract the user identifier: Parse the URL to identify the embedded internal Moodle user ID parameter, which is inadvertently included in the URL despite the anonymous submission setting.
  4. Correlate the user ID: Cross-reference the extracted internal user ID with other Moodle data (e.g., user profile pages, enrollment lists) to de-anonymize the submitting student (Github Advisory, Red Hat Bugzilla).

Mitigation and workarounds

Moodle has released patched versions addressing this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1 (Github Advisory). Administrators should upgrade to one of these versions as the primary remediation. As interim measures, administrators can review and audit anonymous assignment submission URLs for exposed user identifiers, and implement network controls or access restrictions to limit who can view submission-related URLs (Moodle Forum).

Community reactions

Red Hat tracked this vulnerability via their security response process and assigned it medium severity, with the bug filed by OSIDB in December 2025 (Red Hat Bugzilla). The GitHub Advisory Database rated it as "Moderate" severity. No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability database entries.

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77143HIGH8.8
  • PHP logoPHP
  • composer://jweiland/pforum
NoYesAug 25, 2026
CVE-2026-77142HIGH8.8
  • PHP logoPHP
  • composer://jweiland/yellowpages2
NoYesAug 25, 2026
CVE-2026-77146HIGH8.3
  • PHP logoPHP
  • composer://in2code/femanager
NoYesAug 25, 2026
CVE-2026-77145HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026
CVE-2026-77144HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management