REDHAT-BUG-2543634: XSS
A flaw was found in Moodle. Insufficient escaping in templates used to display forum posts resulted in a cross-site scripting (XSS) risk, allowing a stored script to execute in the browser of another user who views the affected forum post.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker must be able to create or modify a forum post containing a stored script. The script executes when another user views the affected post.
Who is exposed to the stored script?
Users who view a forum post containing the malicious stored content are exposed in their browser. The provided information does not identify any particular user role or permission level required to view the post.
How can I determine whether exploitation may have occurred?
Review forum posts for unexpected or suspicious script-like content, especially posts created or edited by untrusted users. The available information does not provide specific indicators of compromise or detection guidance.