MSA-25-0061: User IDs exposed in URLs when using anonymous submissions in assignment

Inhalt

by Michael Hawkins. When blind marking is enabled for an assignment, user IDs remained visible on the assignment submissions page instead of being masked. Severity/Risk: Minor Versions affected: 5.1, 5.0 to 5.0.3, 4.5 to 4.5.7, 4.4 to 4.4.11, 4.1 to 4.1.21 and earlier unsupported versions Versions fixed: 5.1.1, 5.0.4, 4.5.8, 4.4.12 and 4.1.22 Reported by: Mihail Geshoski CVE identifier: CVE-2025-67857 Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-82808 Tracker issue: MDL-82808 User IDs exposed in URLs when using anonymous submissions in assignment

Verknuepfte CVEs

CVE-ID Severity (CVE.org) CVSS (CVE.org) EPSS EPSS-% Veroeffentlicht (CVE.org)

CVE-2025-67857

- - - -

Quellen-Details

Bezeichnung Name Kategorie Tags Zielgruppe Sprache Feed-URL
Moodle Security Announcements

moodle

vendor_advisory cms - de https://moodle.org/rss/file.php/154821/7ef1adaa0762dfdd7cd390868b6d9f2b/mod_forum/996/rss.xml