Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
A cross-site scripting (XSS) vulnerability has been identified in Moodle. This issue arises from inadequate validation of user input in the formula editor's arithmetic expression fields. A remote attacker could exploit this flaw by injecting malicious scripts into these fields. When other users view the expressions, the injected scripts would execute in their web browsers, potentially compromising their data or allowing unauthorized actions.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser. This could lead to unauthorized actions being performed on behalf of the user or the compromise of sensitive data, such as cookies containing session information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.