Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | moodle | 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, and earlier unsupported versions contain a cross-site scripting vulnerability via the redirect_uri parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/moodle/moodle-xss.yaml | POC Details |
| 2 | Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 contain a reflected XSS and open redirect caused by insufficient sanitization of the redirect URI in the LTI authorization endpoint, letting attackers execute scripts or redirect users maliciously, exploit requires crafted URL with malicious redirect URI. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-32478.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet