VYPR
Medium severity5.4NVD Advisory· Published Oct 29, 2023· Updated Jun 17, 2026

CVE-2023-46858

CVE-2023-46858

Description

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Moodle/Moodlecpe-rescue3 versions
    (expand)+ 2 more
    • (no CPE)
    • (no CPE)
    • cpe:2.3:a:moodle:moodle:4.3.0:*:*:*:*:*:*:*
  • osv-coords
    Range: >= 4.3.0, < 4.3.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.