Cross Site Scripting Vulnerability in Moodle CMS by Moodle
CVE-2024-37674

5.5MEDIUM

Key Information:

Vendor

Moodle

Vendor
CVE Published:
20 June 2024

What is CVE-2024-37674?

A Cross Site Scripting (XSS) vulnerability has been identified in Moodle CMS version 3.10, which allows a remote attacker to inject and execute arbitrary code. This can be exploited via the Field Name parameter when creating a new activity, potentially compromising the security of the web application and exposing sensitive data. Users of Moodle CMS are advised to review their installations for any vulnerabilities and consider applying security updates.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.