← Zuruck zu CVEs
CVE-2025-67852
LOW3.5
Beschreibung
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
CVE Details
CVSS v3.1 Bewertung3.5
SchweregradLOW
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionREQUIRED
Veroffentlicht2/3/2026
Zuletzt geandert2/11/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
moodle:moodle
Schwachen (CWE)
CWE-601
Referenzen
https://access.redhat.com/security/cve/CVE-2025-67852(patrick@puiterwijk.org)
https://bugzilla.redhat.com/show_bug.cgi?id=2423844(patrick@puiterwijk.org)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.