CVE-2025-67852 PUBLISHED

Moodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.

Assigner: fedora
Reserved: 12.12.2025 Published: 03.02.2026 Updated: 03.02.2026

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 3.5

Product Status

Package Collection https://github.com/moodle/moodle/
Package Name moodle
Versions Default: unaffected
  • affected from 4.1.0 to 4.1.22 (excl.)
  • affected from 4.4.0 to 4.4.12 (excl.)
  • affected from 4.5.0 to 4.5.8 (excl.)
  • affected from 5.0.0 to 5.0.4 (excl.)
  • affected from 5.1.0 to 5.1.1 (excl.)

Credits

  • Red Hat would like to thank Paolo Lazzaroni for reporting this issue.

References

Problem Types

  • URL Redirection to Untrusted Site ('Open Redirect') CWE