CVE-2025-26529
CVSS 3.1 Score 8.3 of 10 (high)
Details
Published Feb 24, 2025
CWE ID 79
Summary
CVE-2025-26529 is a stored XSS vulnerability affecting a specific site administration live log. The log, which displays description information, did not undergo sufficient sanitization, leaving it open to attackers to inject malicious code. Successful exploitation could allow attackers to execute arbitrary scripts in the context of the affected user, potentially leading to unauthorized access or data theft. Users are advised to update their systems and implement additional security measures to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Moodle
Affected Vendors
- Moodle