CVE-2025-67851

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:5.1.0:-:*:*:*:*:*:*

History

17 Jun 2026, 09:58

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en moodle. Esta vulnerabilidad de inyección de fórmulas ocurre cuando los campos de datos se exportan sin el escape adecuado. Un atacante remoto podría explotar esto al proporcionar datos maliciosos que, al exportarse y abrirse en una hoja de cálculo, permiten la ejecución de fórmulas arbitrarias. Esto puede llevar a un compromiso de la integridad de los datos y a operaciones no intencionadas dentro de la hoja de cálculo.

11 Feb 2026, 18:32

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2025-67851 - () https://access.redhat.com/security/cve/CVE-2025-67851 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2423841 - () https://bugzilla.redhat.com/show_bug.cgi?id=2423841 - Issue Tracking, Third Party Advisory
References () https://moodle.org/mod/forum/discuss.php?d=471301 - () https://moodle.org/mod/forum/discuss.php?d=471301 - Vendor Advisory
First Time Moodle moodle
Moodle
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:5.1.0:-:*:*:*:*:*:*

03 Feb 2026, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 11:15

Updated : 2026-06-17 09:58


NVD link : CVE-2025-67851

Mitre link : CVE-2025-67851

CVE.ORG link : CVE-2025-67851


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File