CyberRota Analysis
AI-GeneratedA vulnerability in Moodle allows for insufficient sanitization of username input on the password reset page, enabling remote attackers to perform cross-site scripting (XSS) attacks. By tricking an unauthenticated user into clicking a malicious password reset link, attackers can execute arbitrary scripts in the user's browser, potentially leading to data theft or session hijacking. Organizations using Moodle should prioritize addressing this issue to protect their users from potential exploitation.
Original NVD Description
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Related CVEs
Other vulnerabilities affecting the same vendor(s)