- Description
- Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.
- Source
- cve@mitre.org
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 8.9
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-79
- Hype score
- Not currently trending
Thanks for my birthday gifts @MITREcorp Happy birthday 26 ! CVE-2025-60511 CVE-2025-60506 CVE-2025-60507
@onurcangenc1999
21 Oct 2025
196 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-60507 Cross-Site Scripting in Moodle GeniAI Plugin Allows Authenticated PDF Payload Execution https://t.co/IruSzEt0H5
@VulmonFeeds
21 Oct 2025
89 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-60507 pertains to a **Cross-Site Scripting (XSS)** vulnerability within the Moodle GeniAI plugin (version 2.3.6), specifically the `local_geniai` component. This vulnerability allows an authenticated user with at least a Teacher role to upload a specially crafted PDF
@CveTodo
21 Oct 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-60507 Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScri… https://t.co/1lkkmTNUke
@CVEnew
21 Oct 2025
300 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-60507: HIGH] Beware of Cross Site Scripting (XSS) vulnerability in Moodle GeniAI plugin. An authenticated user can upload malicious PDFs with embedded JavaScript, affecting other users' browsers.#cve,CVE-2025-60507,#cybersecurity https://t.co/Ck0rS87Zhp https://t.co/tR5
@CveFindCom
21 Oct 2025
129 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes