CVE-2023-23921: Moodle: reflected xss risk in some returnurl parameters
MSA-23-0001: Reflected XSS risk in some returnurl parameters
Some returnurl parameters required additional sanitizing to prevent a reflected XSS risk.
Versions affected: 4.1, 4.0 to 4.0.5, 3.11 to 3.11.11, 3.9 to 3.9.18 and earlier unsupported versions Versions fixed: 4.1.1, 4.0.6, 3.11.12 and 3.9.19
Other sources
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23921.
What is the severity of CVE-2023-23921?
The severity of CVE-2023-23921 is high.
How does CVE-2023-23921 affect Moodle?
CVE-2023-23921 affects Moodle versions 3.9.0 to 3.9.19, 3.11.0 to 3.11.12, 4.0.0 to 4.0.6, and 4.1.0.
How can a remote attacker exploit CVE-2023-23921?
A remote attacker can trick a victim to follow a specially crafted link, allowing them to execute arbitrary HTML and script code in the user's browser within the context of the vulnerable Moodle website.
How can I fix CVE-2023-23921?
To fix CVE-2023-23921, update your Moodle installation to version 4.1.1, 4.0.6, 3.11.12, or 3.9.19.