Executive brief
Joomdle is a Joomla extension used to integrate the Moodle learning management system into Joomla websites, allowing for shared content and single sign-on. A security flaw in this extension could allow an attacker to trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could lead to the theft of login sessions or sensitive information from the user's account on the affected website.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Joomdle extension for Joomla (versions prior to 3.1.1). The flaw is located within the Moodle wrapper endpoint, which fails to properly sanitize the 'goto' URL parameter. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing JavaScript and persuading a victim to visit it. Successful exploitation allows the execution of arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is addressed in Joomdle version 3.1.1.
Affected products
- joomdle.com Joomdle 0.7.0 - 3.0.1
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory