Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4273 | The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. |
Github GHSA |
GHSA-h697-w4ph-7pcx | Moodle has a stored XSS in ddimageortext question type |
Fri, 08 Aug 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Mon, 24 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. | |
| Title | Stored XSS in ddimageortext question type | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-02-24T20:13:02.785Z
Reserved: 2025-02-12T13:29:39.336Z
Link: CVE-2025-26528
Updated: 2025-02-24T20:04:15.773Z
Status : Analyzed
Published: 2025-02-24T20:15:33.543
Modified: 2025-08-08T19:38:31.230
Link: CVE-2025-26528
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA