Description
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
Published: 2024-11-11
Score: 5.4 Medium
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-3194 A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
Github GHSA Github GHSA GHSA-4hjf-6pxr-549h Moodle Cross-site Scripting vulnerability
History

Wed, 23 Apr 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle

Thu, 13 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 11 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 12:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
Title Moodle: xss risk when restoring malicious course backup file
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2025-03-13T14:04:35.671Z

Reserved: 2024-08-13T07:15:00.599Z

Link: CVE-2024-43437

cve-icon Vulnrichment

Updated: 2024-11-11T14:28:20.021Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-11T13:15:04.757

Modified: 2025-04-23T21:28:23.360

Link: CVE-2024-43437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses