BIT-moodle-2024-28593

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2024-28593.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-moodle-2024-28593
Aliases
Published
2025-05-02T06:18:27Z
Modified
2026-09-08T08:48:15Z
Summary
[none]
Details

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

Database specific
{
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.3.3
Fixed
4.3.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2024-28593.json"