CVE-2024-38274

CVE-2024-38274: moodle: stored XSS via calendar's event title when deleting the event

Vendor Moodle
Product Moodle
Weakness CWE-79 · XSS
Published June 18, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

01Description

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Key dates

02Disclosure timeline

June 18, 2024 CVE published
February 13, 2025 Record updated