CVE-2025-67852
LOWMoodle < 4.1.22 - Open Redirect
Title source: ruleDescription
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
Scores
CVSS v3
3.5
EPSS
0.0001
EPSS Percentile
2.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Classification
CWE
CWE-601
Status
published
Affected Products (3)
moodle/moodle
< 4.1.22
moodle/moodle
moodle/moodle
< 4.1.22Packagist
Timeline
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026