CVE-2025-60507: XSS
Cross site scripting vulnerability in Moodle GeniAI plugin (localgeniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60507?
CVE-2025-60507 has a high severity due to the potential for cross site scripting attacks that can affect both users and data security.
How do I fix CVE-2025-60507?
To fix CVE-2025-60507, update the Moodle GeniAI plugin to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-60507?
CVE-2025-60507 affects authenticated users with Teacher roles who upload PDF files to the Moodle GeniAI plugin.
What type of vulnerability is CVE-2025-60507?
CVE-2025-60507 is a cross site scripting (XSS) vulnerability.
What are the consequences of CVE-2025-60507?
The consequences of CVE-2025-60507 include the possibility of executing malicious scripts on other users' browsers, leading to data theft or unauthorized actions.