A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Vendors & Products |
Moodle
Moodle moodle |
Tue, 03 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated. | |
| Title | Moodle: moodle: cross-site scripting (xss) via improper sanitization of ai prompt responses | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published: 2026-02-03T10:52:01.127Z
Updated: 2026-02-04T04:55:49.524Z
Reserved: 2025-12-12T13:00:24.330Z
Link: CVE-2025-67849
Updated: 2026-02-03T17:01:50.675Z
Status : Awaiting Analysis
Published: 2026-02-03T11:15:55.067
Modified: 2026-02-03T16:44:03.343
Link: CVE-2025-67849
No data.