VYPR

Jmol plugin

by Moodle

CVEs (2)

  • CVE-2025-34031HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.03

    A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from…

  • CVE-2025-34032MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute…