Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
A cross-site scripting (XSS) vulnerability has been identified in Moodle, caused by inadequate sanitization of AI prompt responses. This flaw enables attackers to inject malicious HTML or scripts into web pages. When these compromised pages are viewed by other users, it could result in session theft or manipulation of the user interface.
Exploitation of this vulnerability allows for cross-site scripting attacks, where injected scripts are executed in the context of the user's browser. This could lead to theft of session cookies, including those of users with administrative privileges, or unauthorized manipulation of the user interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.