CVE-2025-67853Disclosure(moodle / moodle)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • moodle

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
moodle

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-03: 2Technical Details · 2026-02-03: 102-03
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-67853 Moodle Confirmation Email Service Vulnerability Enables User Cred... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-67853 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post references CVE-2025-67853 with a link but provides no additional details on the vulnerability, exploitation, or mitigation.

    0000051
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-67853 A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to m… https://www.cve.org/CVERecord?id=CVE-2025-67853

    Post summary

    The text reports a new Moodle vulnerability (CVE-2025-67853) involving improper rate limiting on the confirmation email service, with no PoC, exploit, active exploitation, patch, or false positive claims provided.

    00000187
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmoodlemoodle---
Appmoodlemoodle5.1.0--

Explore more