High severity8.8NVD Advisory· Published Sep 17, 2018· Updated Jun 17, 2026
CVE-2018-14631
CVE-2018-14631
Description
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 3.3, < 3.3.8 | 3.3.8 |
moodle/moodlePackagist | >= 3.4, < 3.4.5 | 3.4.5 |
moodle/moodlePackagist | >= 3.5, < 3.5.2 | 3.5.2 |
Affected products
1Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- moodle.org/mod/forum/discuss.phpnvdPatchVendor AdvisoryWEB
- www.securityfocus.com/bid/105371nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-gqrp-qhv8-phrvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-14631ghsaADVISORY
News mentions
0No linked articles in our index yet.