CVE-2024-34006

MEDIUM

Moodle < 4.1.10 and 4.3.0-4.3.4 - Cross-Site Scripting in Site Log Report

Title source: llm
STIX 2.1

Description

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0042
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-838
Status published
Products (2)
moodle/moodle < 4.1.10
moodle/moodle 4.3.0 - 4.3.4Packagist
Published May 31, 2024
Tracked Since Feb 18, 2026