CVE-2014-3551

Moodle < 2.3.11, 2.4.x < 2.4.11, 2.5.x < 2.5.7, 2.6.x < 2.6.4, 2.7.x < 2.7.1 - XSS via Rubric Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3551. PoCs published by JavaGarcia.

AI-analyzed exploit summary This repository contains a writeup describing multiple XSS vulnerabilities in Moodle's advanced-grading implementation, specifically in rubric qualification and rating fields. The README provides details on the vulnerable endpoint and parameters but does not include exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

Exploits (1)

nomisec WRITEUP
by JavaGarcia · poc
https://github.com/JavaGarcia/CVE-2014-3551

This repository contains a writeup describing multiple XSS vulnerabilities in Moodle's advanced-grading implementation, specifically in rubric qualification and rating fields. The README provides details on the vulnerable endpoint and parameters but does not include exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1
Auth required
Prerequisites: Authenticated user access to Moodle · Ability to input data into rubric qualification or rating fields
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/07/21/1
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=264273
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68763

Scores

EPSS 0.0025
EPSS Percentile 48.4%

Details

CWE
CWE-79
Status published
Products (36)
moodle/moodle 2.5.0
moodle/moodle 2.5.1
moodle/moodle 2.5.2
moodle/moodle 2.5.3
moodle/moodle 2.5.4
moodle/moodle 2.5.5
moodle/moodle 2.5.6
moodle/moodle 2.3.0
moodle/moodle 2.3.1
moodle/moodle 2.3.2
... and 26 more
Published Jul 29, 2014
Tracked Since Feb 18, 2026