在 Moodle 中发现了一个漏洞。密码重置页面对用户名输入的处理存在不足,使得远程攻击者能够实施跨站脚本(XSS)攻击。通过诱使未认证用户访问一个经过特殊构造的密码重置链接,攻击者可以在受害者的浏览器中执行任意脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 5.2.0 ~ 5.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet