CVE-2024-37674: XSS
Published Jun 20, 2024
·Updated
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
Affected Software
2 affected components
Moodle moodle
Moodle moodle=3.10.0
Event History
Jun 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37674?
CVE-2024-37674 is classified as a high-severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-37674?
To fix CVE-2024-37674, update your Moodle CMS to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2024-37674?
CVE-2024-37674 specifically affects Moodle CMS version 3.10.
4
What type of vulnerability is CVE-2024-37674?
CVE-2024-37674 is a Cross Site Scripting (XSS) vulnerability.
5
What could happen if CVE-2024-37674 is exploited?
If exploited, CVE-2024-37674 could allow an attacker to execute arbitrary code on the affected Moodle instance.