REDHAT-BUG-2543641: XSS
Published Sep 29, 2026
·Updated
A flaw was found in Moodle. Insufficient escaping of the username on the password reset page allowed a minor cross-site scripting (XSS) risk if an unauthenticated user was tricked into opening a crafted password reset link. The reporter states this did not affect authenticated user sessions; that disclaimer is reflected in the impact assessment here.
Affected Software
1 affected component
Moodle Moodle
Event History
Sep 29, 2026
Data Sourced
via Red Hat·08:37 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An unauthenticated attacker would need to craft a password reset link and trick a user into opening it. The issue is limited to insufficient escaping of the username on the password reset page.
2
Are authenticated user sessions at risk?
No. The reported impact assessment states that authenticated user sessions are not affected.