CVE-2025-67856 | Moodle up to 4.1.21/4.4.11/4.5.7/5.0.3/5.1.0 Badge improper authorization (Nessus ID 297897)
A vulnerability categorized as critical has been discovered in Moodle up to 4.1.21/4.4.11/4.5.7/5.0.3/5.1.0. Affected by this issue is some unknown functionality of the component Badge Handler. Executing a manipulation can lead to improper authorization.
This vulnerability is registered as CVE-2025-67856. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.