Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qfh6-h7j6-fvjv | Moodle formula injection vulnerability |
Wed, 11 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* cpe:2.3:a:moodle:moodle:5.1.0:-:*:*:*:*:*:* |
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Vendors & Products |
Moodle
Moodle moodle |
Tue, 03 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet. | |
| Title | Moodle: moodle: formula injection allows arbitrary formula execution via unescaped data export | |
| Weaknesses | CWE-1236 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-03T17:02:43.231Z
Reserved: 2025-12-12T13:00:24.330Z
Link: CVE-2025-67851
Updated: 2026-02-03T17:02:40.393Z
Status : Analyzed
Published: 2026-02-03T11:15:55.367
Modified: 2026-02-11T18:32:18.400
Link: CVE-2025-67851
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:14:27Z
Github GHSA