CVE-2024-33997: moodle: stored XSS risk when editing another user's equation in equation editor
Additional sanitizing was required when opening the equation editor to prevent a stored Cross-site Scripting (XSS) risk when editing another user's equation.
Other sources
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33997?
CVE-2024-33997 is categorized as a high severity vulnerability due to its potential to allow stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-33997?
To fix CVE-2024-33997, upgrade to Moodle versions 4.1.10, 4.2.7, or 4.3.4 or later.
What type of vulnerability is CVE-2024-33997?
CVE-2024-33997 is a stored Cross-site Scripting (XSS) vulnerability affecting the equation editor in Moodle.
Who is affected by CVE-2024-33997?
Users of Moodle versions prior to 4.1.10, 4.2.7, and 4.3.4 are at risk of exploitation from CVE-2024-33997.
What are the potential impacts of CVE-2024-33997?
The exploitation of CVE-2024-33997 can lead to unauthorized script execution in users' browsers, potentially compromising their data.