Impact
The vulnerability arises from improper sanitization of the username field on Moodle's password reset page. A remote attacker can craft a link containing an attacker‑provided username that is not escaped before being rendered in the browser, leading to cross‑site scripting. If a victim opens the link, the attacker could execute arbitrary JavaScript in that victim’s browser session, potentially allowing data theft, cookie hijacking, or other malicious actions. The weakness is a classic stored XSS flaw categorized as CWE‑79.
Affected Systems
Moodle, the open‑source learning management system, is affected. The advisory does not list specific affected releases, so all unpatched Moodle installations should be considered vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate impact. No EPSS score was published, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low to moderate likelihood of exploitation. The attack requires an unauthenticated user to click a malicious link; thus social engineering is a prerequisite. Once triggered, the injected script runs with the victim’s browser privileges, but the scope is limited to the victim’s session and does not compromise the Moodle server itself.
OpenCVE Enrichment