Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6mmv-f6c6-v6q8 | Moodle vulnerable to Cross-site Scripting |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 03 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions. | |
| Title | Moodle: moodle: cross-site scripting vulnerability via inadequate input filtering in formula editor | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-03T17:02:21.882Z
Reserved: 2025-12-12T13:00:24.330Z
Link: CVE-2025-67850
Updated: 2026-02-03T17:02:17.320Z
Status : Awaiting Analysis
Published: 2026-02-03T11:15:55.213
Modified: 2026-02-03T16:44:03.343
Link: CVE-2025-67850
No data.
OpenCVE Enrichment
No data.
Github GHSA