CVE-2021-47857
HIGHMoodle 3.10.3 - Stored Cross-Site Scripting in Calendar Event Subtitle Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47857. PoCs published by Vincent666.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Moodle 3.10.3 via the 'label' field in the calendar event creation form. The payload is injected into the subtitle track URL label, which is then rendered when the event is viewed.
Description
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Moodle 3.10.3 via the 'label' field in the calendar event creation form. The payload is injected into the subtitle track URL label, which is then rendered when the event is viewed.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N