CVE-2025-67857
Moodle: moodle: data exposure of user identifiers in urls
4.3
MEDIUM
CVSS 3.1
EPSS 0.02%
Description
A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.
How to fix CVE-2025-67857
To remediate CVE-2025-67857, upgrade the affected package to a fixed version below.
- —upgrade to 4.1.21 or later
- —upgrade to 4.1.22 or later
Is CVE-2025-67857 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.1.21, >= 4.4.0, < 4.4.11, >= 4.5.0, < 4.5.8, >= 5.0.0, < 5.0.4, >= 5.1.0, < 5.1.1
- from 0, < 4.1.22
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |