CVE-2024-33998: moodle: stored XSS via user's name on participants page when opening some options
Published May 31, 2024
·Updated
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle<4.1.10
4.1.10
composer/moodle/moodle>=4.2.0<4.2.7
4.2.7
composer/moodle/moodle>=4.3.0<4.3.4
4.3.4
Moodle moodle<4.1.10
Moodle moodle>=4.2.0<4.2.7
Moodle moodle>=4.3.0<4.3.4
Event History
May 31, 2024
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33998?
CVE-2024-33998 is classified as a moderate severity vulnerability due to its stored XSS risk.
2
How do I fix CVE-2024-33998?
To mitigate CVE-2024-33998, upgrade to Moodle versions 4.1.10, 4.2.7, or 4.3.4 or higher.
3
What kind of attack does CVE-2024-33998 allow for?
CVE-2024-33998 allows for a stored cross-site scripting (XSS) attack when participants' names are insufficiently escaped.
4
In which versions of Moodle is CVE-2024-33998 present?
CVE-2024-33998 is present in Moodle versions prior to 4.1.10, from 4.2.0 to below 4.2.7, and from 4.3.0 to below 4.3.4.
5
Who is affected by CVE-2024-33998?
Users of the affected Moodle versions are at risk of exploitation through CVE-2024-33998.