CVE-2024-34006

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

30 May 2025, 16:48

Type Values Removed Values Added
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
CWE CWE-838
References () https://moodle.org/mod/forum/discuss.php?d=458395 - () https://moodle.org/mod/forum/discuss.php?d=458395 - Vendor Advisory
First Time Moodle
Moodle moodle

31 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 21:15

Updated : 2025-05-30 16:48


NVD link : CVE-2024-34006

Mitre link : CVE-2024-34006


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-838

Inappropriate Encoding for Output Context