Junglewise Threat Intelligence

CVE-2017-2578: Moodle XSS in assignment submission page

CVE-2017-2578 · Severity: medium · CVSS 6.1 · Published 2017-01-20

Technologies: Moodle. Vendors: Moodle.

Executive brief

Moodle, a widely used learning management system, contains a security flaw in its assignment submission page. This vulnerability allows an attacker to inject malicious scripts that execute in the browser of other users, such as teachers or students. Successful exploitation could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Moodle versions 3.1.x (up to 3.1.3) and 3.2.0 within the assignment submission component. The flaw stems from improper neutralization of user-supplied input before it is rendered on the page (CWE-79). An attacker can exploit this by tricking a user into visiting a specially crafted URL or interacting with malicious content on the submission page. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized data access. Moodle has released patches to address this issue.

Affected products

  • Moodle Moodle 3.1.0 to 3.1.3, 3.2.0

Timeline

  • 2017-01-20: disclosed
  • 2017-01-20: advisory

References

Related threats