PT-2024-22490 · Moodle · Moodle

Published

2024-03-22

·

Updated

2025-05-02

·

CVE-2024-28593

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle version 4.3.3
Description The Chat activity in Moodle allows students to insert potentially unwanted HTML elements, such as A or IMG elements, or HTML content that can lead to performance degradation. The vendor's documentation notes that users can utilize HTML code in their text, including inserting images, playing sounds, or creating differently colored and sized text. It is also mentioned that the Chat activity is due to be removed from standard Moodle.
Recommendations For Moodle version 4.3.3, consider disabling the Chat activity until a patch is available to prevent potential performance degradation and unauthorized HTML element insertion. Restrict access to the Chat module to minimize the risk of exploitation. Avoid using HTML code in the Chat activity until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

XSS

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2024-28593
CVE-2024-28593
GHSA-F6MH-79VH-2HV7

Affected Products

Moodle