CVE-2024-43437
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-43437 is a newly identified vulnerability affecting the Moodle learning platform. The issue arises from insufficient sanitization of data during file restores. Maliciously crafted backup files can exploit this vulnerability, leading to a cross-site scripting (XSS) risk. An attacker could inject malicious scripts into a Moodle website, potentially gaining unauthorized access to user information or taking control of the affected site. To mitigate this risk, it's recommended that users update their Moodle installations as soon as a patch becomes available. In the interim, it's essential to apply security best practices, such as regularly checking and filtering backup files before restoration.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.