CVE-2024-43439: Moodle: reflected xss via h5p error message
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43439?
CVE-2024-43439 has been classified as a moderate severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2024-43439?
To fix CVE-2024-43439, update your Moodle installation to the latest version that contains the necessary sanitization improvements.
Who is affected by CVE-2024-43439?
CVE-2024-43439 affects users of Moodle who utilize H5P functionalities without the appropriate security patches.
What is the nature of the vulnerability in CVE-2024-43439?
CVE-2024-43439 is a reflected cross-site scripting (XSS) vulnerability that requires additional sanitization of error messages within the H5P functionality.
Is CVE-2024-43439 being actively exploited?
As of now, there have been no reported instances of CVE-2024-43439 being actively exploited in the wild, but it poses a risk to affected systems.