CVE-2025-67849
HIGHMoodle < 4.5.8 - XSS
Title source: ruleDescription
A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.
Scores
CVSS v3
7.3
EPSS
0.0001
EPSS Percentile
1.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (3)
moodle/moodle
< 4.5.8
moodle/moodle
moodle/moodle
< 4.1.22Packagist
Timeline
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026