GHSA-rfv4-mv3r-qx66MediumCVSS 4.3

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.

🔗 References (6)