CVE-2024-38274: moodle: stored XSS via calendar's event title when deleting the event
Published Jun 18, 2024
·Updated
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
Affected Software
10 affected componentsFixes available
composer/moodle/moodle<4.1.11
4.1.11
composer/moodle/moodle>=4.2.0-beta<4.2.8
4.2.8
composer/moodle/moodle>=4.3.0-beta<4.3.5
4.3.5
composer/moodle/moodle>=4.4.0-beta<4.4.1
4.4.1
Moodle Moodle>=4.1.0<4.1.11
Moodle Moodle>=4.2.0<4.2.8
Moodle Moodle>=4.3.0<4.3.5
Moodle Moodle=4.4.0
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Event History
Jun 18, 2024
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
SeverityAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-38274?
CVE-2024-38274 has been classified with a medium severity due to its potential for stored cross-site scripting (XSS).
2
How do I fix CVE-2024-38274?
You can fix CVE-2024-38274 by upgrading to Moodle version 4.1.11, 4.2.8, 4.3.5, or 4.4.1 or later.
3
What is the impact of CVE-2024-38274?
CVE-2024-38274 can lead to a stored XSS vulnerability that affects the security of user data and application integrity.
4
Which versions of Moodle are affected by CVE-2024-38274?
CVE-2024-38274 affects versions of Moodle prior to 4.1.11, 4.2.8, 4.3.5, and 4.4.1.
5
Is there a workaround for CVE-2024-38274?
There are no reported workarounds for CVE-2024-38274; the recommended action is to upgrade to a patched version.