CVE-2025-3643: Moodle: reflected xss risk in policy tool
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
Other sources
The return URL in the policy tool required extra sanitizing to prevent a reflected XSS risk.
Versions affected: 4.5 to 4.5.3, 4.4 to 4.4.7, 4.3 to 4.3.11, 4.1 to 4.1.17 and earlier unsupported versions.
Versions fixed: 4.5.4, 4.4.8, 4.3.12 and 4.1.18
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3643?
CVE-2025-3643 has a moderate severity rating due to its reflected Cross-site scripting (XSS) risk.
How do I fix CVE-2025-3643?
To fix CVE-2025-3643, it is recommended to update Moodle to a version that includes the necessary sanitization improvements.
Which versions of Moodle are affected by CVE-2025-3643?
Moodle versions 4.1 to 4.5.3 are affected by CVE-2025-3643.
What type of vulnerability is CVE-2025-3643?
CVE-2025-3643 is a reflected Cross-site scripting (XSS) vulnerability.
Can CVE-2025-3643 be exploited remotely?
Yes, CVE-2025-3643 can be exploited remotely through specially crafted URLs.