PT-2025-42910 · WordPress · Moodle Pdf Annotator
Published
2025-10-21
·
Updated
2025-10-21
·
CVE-2025-60506
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle PDF Annotator plugin version 1.5 release 9
Description
The Moodle PDF Annotator plugin contains a flaw that permits stored cross-site scripting (XSS) through the Public Comments feature. An attacker possessing a low-privileged account, such as a Student, can inject arbitrary JavaScript payloads into a comment. When another user—including Students, Teachers, or Administrators—views the annotated PDF, the injected payload is executed within their browser. This can result in session hijacking or credential theft. The vulnerable feature allows for the injection of malicious code via the
Public Comments functionality.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle Pdf Annotator