vendor:
Moodle
by:
farisv
6.1
CVSS
MEDIUM
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: Moodle
Affected Version From: Moodle < 3.6.2
Affected Version To: Moodle < 3.5.4, < 3.4.7, < 3.1.16
Patch Exists: YES
Related CWE: CVE-2019-3810
CPE: a:moodle:moodle
Platforms Tested:
2021
Moodle 3.6.1 – Persistent Cross-Site Scripting (XSS)
The exploit allows for privilege escalation from student to administrator by exploiting a persistent cross-site scripting (XSS) vulnerability (CVE-2019-3810) in Moodle version 3.6.1. The exploit involves uploading an XSS payload and manipulating the first name and surname fields to execute malicious code. If successful, the attacker's account will be added as an administrator.
Mitigation:
Upgrade to Moodle version 3.6.2 or above. Apply security patches provided by the vendor.