CVE-2025-67851
A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2025-67851, https://bugzilla.redhat.com/showbug.cgi?id=2423841, https://moodle.org/mod/forum/discuss.php?d=471301, https://bugzilla.redhat.com/showbug.cgi?id=2423841
