CVE 4.3 MEDIUM

Moodle: moodle: data exposure of user identifiers in urls_CVE-2025-67857

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Description

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

Basic Information

ID CVE-2025-67857
Source fedora
Published Feb 3, 2026 at 10:52

Affected Product

Version 5.1.0
Affected Versions 4.1.0
4.4.0
4.5.0
5.0.0
5.1.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.