Cross-Site Scripting Flaw in Virtual Programming Lab for Moodle
CVE-2024-34312

6.1MEDIUM

Key Information:

Vendor

Moodle

Vendor
CVE Published:
24 June 2024

What is CVE-2024-34312?

A cross-site scripting (XSS) vulnerability has been identified in the Virtual Programming Lab component of Moodle, affecting versions up to v4.2.3. The flaw originates from the file vplide.js, which can allow attackers to inject malicious scripts. This vulnerability could potentially compromise user inputs and lead to unauthorized actions within the Moodle environment, making it essential for users to apply appropriate security measures.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.