CVE-2014-3544

Moodle < 2.3.11 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.

Exploits (2)

nomisec WORKING POC 1 stars
by aforesaid · poc
https://github.com/aforesaid/MoodleHack
exploitdb WORKING POC
by Osanda Malith Jayathissa · textwebappsphp
https://www.exploit-db.com/exploits/34169

Scores

EPSS 0.0082
EPSS Percentile 74.2%

Details

CWE
CWE-79
Status published
Products (37)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 27 more
Published Jul 29, 2014
Tracked Since Feb 18, 2026