Description
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from improper sanitization of the username field on Moodle's password reset page. A remote attacker can craft a link containing an attacker‑provided username that is not escaped before being rendered in the browser, leading to cross‑site scripting. If a victim opens the link, the attacker could execute arbitrary JavaScript in that victim’s browser session, potentially allowing data theft, cookie hijacking, or other malicious actions. The weakness is a classic stored XSS flaw categorized as CWE‑79.

Affected Systems

Moodle, the open‑source learning management system, is affected. The advisory does not list specific affected releases, so all unpatched Moodle installations should be considered vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS base score of 4.3 indicates moderate impact. No EPSS score was published, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low to moderate likelihood of exploitation. The attack requires an unauthenticated user to click a malicious link; thus social engineering is a prerequisite. Once triggered, the injected script runs with the victim’s browser privileges, but the scope is limited to the victim’s session and does not compromise the Moodle server itself.

Generated by OpenCVE AI on September 30, 2026 at 11:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Moodle to the latest released version that addresses the username sanitization issue.
  • If an upgrade is not immediately possible, ensure that the password reset feature is disabled or that usernames are removed from reset URLs and the input field is properly escaped before rendering.
  • Deploy a Content Security Policy that restricts script sources and blocks inline scripts to mitigate the impact of potential XSS.

Generated by OpenCVE AI on September 30, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Title Moodle: xss via password reset link due to insufficient username escaping
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T15:28:08.409Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:15.897

Modified: 2026-09-30T16:20:44.613

Link: CVE-2026-102586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')