CVE-2024-29374: XSS
Published Mar 21, 2024
·Updated
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
Affected Software
2 affected components
composer/moodle/moodle<=3.10.9
Moodle moodle=3.10.9
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-29374?
CVE-2024-29374 has been classified as a high severity Cross-Site Scripting vulnerability.
2
How do I fix CVE-2024-29374?
To fix CVE-2024-29374, upgrade to a version of Moodle newer than 3.10.9.
3
What impact does CVE-2024-29374 have on users?
CVE-2024-29374 allows attackers to inject malicious scripts through the 'GET /?lang=' URL parameter, which can compromise user data.
4
What software is affected by CVE-2024-29374?
CVE-2024-29374 affects Moodle version 3.10.9.
5
How can I detect CVE-2024-29374 in my environment?
You can detect CVE-2024-29374 by scanning your Moodle installation for version 3.10.9 and testing for unauthorized script injection.