CVE-2025-67847: Moodle: moodle: remote code execution via insufficient restore input validation
A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67847?
CVE-2025-67847 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-67847?
To fix CVE-2025-67847, update Moodle to the latest version where the input validation vulnerabilities are addressed.
What systems are affected by CVE-2025-67847?
CVE-2025-67847 affects the Moodle application, specifically versions prior to the patch that addresses the restore input validation issues.
What are the potential impacts of CVE-2025-67847?
Exploitation of CVE-2025-67847 allows an attacker to execute arbitrary code on the server, which could lead to a complete system compromise.
Is user authentication required to exploit CVE-2025-67847?
Yes, an attacker needs access to the restore interface in Moodle to exploit CVE-2025-67847.