A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

Project Subscriptions

No data.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qfh6-h7j6-fvjv Moodle formula injection vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.
Title Moodle: moodle: formula injection allows arbitrary formula execution via unescaped data export
Weaknesses CWE-1236
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-03T17:02:43.231Z

Reserved: 2025-12-12T13:00:24.330Z

Link: CVE-2025-67851

cve-icon Vulnrichment

Updated: 2026-02-03T17:02:40.393Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-03T11:15:55.367

Modified: 2026-02-03T16:44:03.343

Link: CVE-2025-67851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses