Cross-Site Scripting Flaw in Virtual Programming Lab for Moodle
CVE-2024-34312
6.1MEDIUM
What is CVE-2024-34312?
A cross-site scripting (XSS) vulnerability has been identified in the Virtual Programming Lab component of Moodle, affecting versions up to v4.2.3. The flaw originates from the file vplide.js, which can allow attackers to inject malicious scripts. This vulnerability could potentially compromise user inputs and lead to unauthorized actions within the Moodle environment, making it essential for users to apply appropriate security measures.