CVE-2025-67851 PUBLISHED

Moodle: moodle: formula injection allows arbitrary formula execution via unescaped data export

Assigner: fedora
Reserved: 12.12.2025 Published: 03.02.2026 Updated: 03.02.2026

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
CVSS Score: 6.1

Product Status

Package Collection https://github.com/moodle/moodle/
Package Name moodle
Versions Default: unaffected
  • affected from 4.1.0 to 4.1.22 (excl.)
  • affected from 4.4.0 to 4.4.12 (excl.)
  • affected from 4.5.0 to 4.5.8 (excl.)
  • affected from 5.0.0 to 5.0.4 (excl.)
  • affected from 5.1.0 to 5.1.1 (excl.)

Credits

  • Red Hat would like to thank Brendan Heywood for reporting this issue.

References

Problem Types

  • Improper Neutralization of Formula Elements in a CSV File CWE