CVE-2023-5547Cross-site Scripting in Moodle

Severity
6.1MEDIUMNVD
CNA3.3
EPSS
0.1%
top 65.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9

Description

The course upload preview contained an XSS risk for users uploading unsafe data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDmoodle/moodle3.9.03.9.24+4
Packagistmoodle/moodle< 4.3.0-rc2

Also affects: Fedora 37, 38, 39, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

4
OSV
Moodle Cross-site Scripting vulnerability2023-11-09
CVEList
Moodle: xss risk when previewing data in course upload tool2023-11-09
OSV
CVE-2023-5547: The course upload preview contained an XSS risk for users uploading unsafe data2023-11-09
GHSA
Moodle Cross-site Scripting vulnerability2023-11-09
CVE-2023-5547 — Cross-site Scripting in Moodle | cvebase