PT-2025-7686 · Moodle+2 · Moodle+2

Nightbloodz

·

Published

2025-02-18

·

Updated

2026-01-02

·

CVE-2025-26529

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 4.5.4-alt1
Description The issue is a stored Cross-Site Scripting (XSS) risk within the site administration live log. Insufficient sanitization of description information displayed in this log allows for the injection of malicious scripts. Exploitation of this issue could potentially lead to remote code execution (RCE) and account takeover. Proof-of-concept (PoC) exploits have been published. The vulnerability stems from a lack of protection measures for the structure of web pages.
Recommendations Upgrade to Moodle version 4.5.4-alt1 or later to address this issue.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
BDU:2025-02329
BIT-MOODLE-2025-26529
CVE-2025-26529
GHSA-WR88-X8CM-7CGQ

Affected Products

Alt Linux
Moodle
Red Os