PT-2024-22490 · Moodle · Moodle
Published
2024-03-22
·
Updated
2025-05-02
·
CVE-2024-28593
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle version 4.3.3
Description
The Chat activity in Moodle allows students to insert potentially unwanted HTML elements, such as
A or IMG elements, or HTML content that can lead to performance degradation. The vendor's documentation notes that users can utilize HTML code in their text, including inserting images, playing sounds, or creating differently colored and sized text. It is also mentioned that the Chat activity is due to be removed from standard Moodle.Recommendations
For Moodle version 4.3.3, consider disabling the Chat activity until a patch is available to prevent potential performance degradation and unauthorized HTML element insertion. Restrict access to the Chat module to minimize the risk of exploitation. Avoid using HTML code in the Chat activity until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moodle