VDB
CVE-2025-26525
CVE-2025-26525
PUBLISHED
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
EPSS 0.21% · 43.8th percentile
Risk Scores
EPSS Score
0.21%
43.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | moodle | 4.4.0, 4.1.0, 4.3.0 |
| Bitnami | moodle | 4.1.0, 4.3.0, 4.4.0 |
Exploit Intelligence
- CIRCL seen: CVE-2025-26525 (circl-sighting)
- CIRCL seen: CVE-2025-26525 (circl-sighting)
- https://moodle.org/mod/forum/discuss.php?d=466141 (circl)
- https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84136 (circl)
Timeline
- Feb 17, 2025 CVE Published
- Feb 24, 2025 PoC Published
- Feb 24, 2025 PoC Published
- Feb 27, 2025 EPSS Score
- Mar 13, 2025 EPSS Score
- Mar 16, 2025 Coalition ESS Score
- Mar 27, 2025 EPSS Score
- Apr 10, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 8, 2025 EPSS Score
- May 22, 2025 EPSS Score
- Jun 5, 2025 EPSS Score