
CVE-2025-67856 A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted wi… https://www.cve.org/CVERecord?id=CVE-2025-67856
Post summary
A newly identified authorization flaw in Moodle’s badge awarding process allows unauthorized badge granting due to incomplete role checks; no patches, PoC, or exploitation evidence are provided.


