CVE-2014-3544
Moodle < 2.3.11 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.
Exploits (2)
exploitdb
WORKING POC
by Osanda Malith Jayathissa · textwebappsphp
https://www.exploit-db.com/exploits/34169
References (9)
Scores
EPSS
0.0082
EPSS Percentile
74.2%
Details
CWE
CWE-79
Status
published
Products (37)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 27 more
Published
Jul 29, 2014
Tracked Since
Feb 18, 2026