CVE-2023-5547

LOW

moodle 3.9.0-3.9.23 and <4.3.0-rc2 - Cross-Site Scripting in Course Upload Preview

Title source: llm
STIX 2.1

Description

The course upload preview contained an XSS risk for users uploading unsafe data.

Scores

CVSS v3 3.3
EPSS 0.0014
EPSS Percentile 33.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (6)
fedoraproject/fedora 37
fedoraproject/fedora 38
fedoraproject/fedora 39
moodle/moodle 0 - 4.3.0-rc2Packagist
moodle/moodle 3.9.0 - 3.9.24
redhat/enterprise_linux 7.0
Published Nov 09, 2023
Tracked Since Feb 18, 2026