A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-02-03 11:15
Updated : 2026-02-03 16:44
NVD link : CVE-2025-67857
Mitre link : CVE-2025-67857
CVE.ORG link : CVE-2025-67857
JSON object : View
Products Affected
No product.
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data
