AI description
CVE-2025-26529 is a stored Cross-Site Scripting (XSS) vulnerability found in Moodle's site administration live log functionality. The vulnerability exists because description information displayed in the site administration live log was not properly sanitized. This flaw affects Moodle versions 4.5 to 4.5.1, 4.4 to 4.4.5, 4.3 to 4.3.9, 4.1 to 4.1.15, and earlier unsupported versions. Successful exploitation of this vulnerability could allow attackers to inject malicious scripts that would be executed in the context of other users' browsers when they view the affected live log section in the site administration area. To remediate this vulnerability, users are advised to upgrade to the patched versions: Moodle 4.5.2, 4.4.6, 4.3.10, and 4.1.16. The fix involves implementing proper sanitization for event descriptions in the live log functionality.
- Description
- Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
- Source
- patrick@puiterwijk.org
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.3
- Impact score
- 6
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- patrick@puiterwijk.org
- CWE-79
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
29
"PoC for CVE-2025-26529: Moodle XSS to RCE Exploit" Credit: https://t.co/fCGtS6Uzqq https://t.co/Nw5oUdiDSn
@DarkWebInformer
2 May 2025
14640 Impressions
44 Retweets
226 Likes
162 Bookmarks
2 Replies
0 Quotes
CVE-2025-26529 Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk. https://t.co/qTjErE7N8w
@CVEnew
24 Feb 2025
383 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[CVE-2025-26529: HIGH] Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.#cybersecurity,#vulnerability https://t.co/0Gq1sG4pS8 https://t.co/4i52bSs3ut
@CveFindCom
24 Feb 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Admin #Account Takeover in Moodle! [#CVE-2025-26529] https://t.co/1ifN7Qdiu2
@UndercodeUpdate
23 Feb 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes