CVE-2014-3544

LAB

Moodle < 2.3.11 - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.

Exploits (2)

exploitdb WORKING POC
by Osanda Malith Jayathissa · textwebappsphp
https://www.exploit-db.com/exploits/34169
nomisec WORKING POC 1 stars
by aforesaid · poc
https://github.com/aforesaid/MoodleHack

References (9)

Core 9
Core References
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/07/21/1
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34169
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/109337
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68756
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=264265

Scores

EPSS 0.0082
EPSS Percentile 74.4%

Lab Environment

COMMUNITY SUSPICIOUS
Community Lab
docker pull mcr.microsoft.com/dotnet/sdk:5.0

Details

CWE
CWE-79
Status published
Products (36)
moodle/moodle 2.4.0
moodle/moodle 2.4.1
moodle/moodle 2.4.2
moodle/moodle 2.4.3
moodle/moodle 2.4.4
moodle/moodle 2.4.5
moodle/moodle 2.4.6
moodle/moodle 2.4.7
moodle/moodle 2.4.8
moodle/moodle 2.4.9
... and 26 more
Published Jul 29, 2014
Tracked Since Feb 18, 2026