Stored XSS Vulnerability in Moodle Forum Posts
CVE-2026-102581
4.6MEDIUM
What is CVE-2026-102581?
A vulnerability in Moodle has been identified that allows insufficient output escaping in templates for forum posts. This security issue permits attackers to inject malicious scripts into forum content, which can be executed in the browsers of users accessing those posts. Successful exploitation can lead to unauthorized actions and exposure of sensitive user data, highlighting the necessity for immediate security updates and awareness among Moodle users.
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Lars Bonczek as the original reporter.
