PT-2025-17918 · Moodle+2 · Moodle+2

Michael Hawkins

·

Published

2025-04-22

·

Updated

2026-01-26

·

CVE-2025-3643

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw was found in the policy tool of Moodle, where the return URL required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
BDU:2025-05100
BIT-MOODLE-2025-3643
CVE-2025-3643
GHSA-HXGG-4QWW-85PH

Affected Products

Alt Linux
Moodle
Red Os