Reflected Cross-Site Scripting Vulnerability in Moodle by Moodle
CVE-2025-3643
What is CVE-2025-3643?
A security flaw in Moodle has been identified that exposes the platform to a reflected Cross-site Scripting (XSS) attack. The vulnerability arises from insufficient sanitization of the return URL in the policy tool, allowing attackers to inject malicious scripts. This flaw can enable cybercriminals to bypass security measures and execute harmful scripts in the context of a user's browser, posing significant risks to user data and privacy. It is crucial for administrators to apply the necessary patches and updates to safeguard their Moodle installations and protect against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved