Impact
The vulnerability arises from insufficient escaping in Moodle’s forum post templates, allowing an attacker to store malicious scripts that execute in the browsers of other users who view the affected post. This stored XSS flaw can be used to hijack user sessions, deface content, or deliver additional malware. The weakness is a classic example of input validation failure (CWE‑79).
Affected Systems
Moodle installations are affected. No specific version range is provided in the available data, so all releases remain potentially vulnerable until a patch is applied. The flaw impacts any user who can post content that will be displayed in the forum display templates.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited broad exploitation evidence to date. However, the attack vector is likely through normal user interaction: an attacker posts a crafted forum entry, and any subsequent user viewing that post is exposed. Compatibility and permissions are typically local to the Moodle instance, so the attack surface is confined to the user base that has access to the forum.
OpenCVE Enrichment