CVE-2014-3547
Moodle < 2.5.7 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in badges/renderer.php in Moodle 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via an external badge.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.7%
Details
CWE
CWE-79
Status
published
Products (14)
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle
... and 4 more
Published
Jul 29, 2014
Tracked Since
Feb 18, 2026