
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67857 is an information disclosure vulnerability in Moodle, the open-source learning management system, where internal user identifiers are inadvertently exposed in URLs during anonymous assignment submissions. This flaw compromises the intended anonymity of submissions, allowing unauthorized viewers to identify students via their internal user IDs. Affected versions include Moodle < 4.1.22, >= 4.4.0-beta and < 4.4.12, >= 4.5.0-beta and < 4.5.8, >= 5.0.0-beta and < 5.0.4, and >= 5.1.0-beta and < 5.1.1. The vulnerability was reported in December 2025 and publicly disclosed on February 3, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) per the GitHub Advisory, or 5.3 (Medium) per NVD scoring (Github Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), where Moodle's anonymous assignment submission workflow fails to strip or obfuscate internal user identifiers before embedding them in URLs (Github Advisory). An attacker or unauthorized viewer who can observe or access these URLs — for example, through browser history, server logs, or a shared link — can extract the internal Moodle user ID of the submitting student. Exploitation requires user interaction (e.g., a victim clicking a link or an observer viewing a URL), and no authentication is required to read the exposed identifier from the URL itself. Patches are available in the Moodle source repository via commits ac30e7e and c6cb8d9 (Github Advisory).
Successful exploitation results in a low-severity confidentiality breach: internal Moodle user IDs are exposed to unauthorized parties, undermining the anonymity guarantees of anonymous assignment submissions (Github Advisory). There is no impact on integrity or availability. While the exposed data is limited to internal user identifiers rather than full personal information, it could enable an adversary to correlate anonymous submissions with specific students, potentially violating privacy policies or academic integrity protections (Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Moodle has released patched versions addressing this vulnerability: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1 (Github Advisory). Administrators should upgrade to one of these versions as the primary remediation. As interim measures, administrators can review and audit anonymous assignment submission URLs for exposed user identifiers, and implement network controls or access restrictions to limit who can view submission-related URLs (Moodle Forum).
Red Hat tracked this vulnerability via their security response process and assigned it medium severity, with the bug filed by OSIDB in December 2025 (Red Hat Bugzilla). The GitHub Advisory Database rated it as "Moderate" severity. No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."