CVE 8.9 HIGH

CVE-2025-60507_CVE-2025-60507

8.9 / 10
HIGH
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:C/UI:R

Description

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.

AI Analysis

Cross-site scripting vulnerability in Moodle GeniAI plugin via PDF upload

Basic Information

ID CVE-2025-60507
Source mitre
Published Oct 21, 2025 at 00:00
Modified Oct 21, 2025 at 18:30

Affected Product

Vendor Moodle
Product Moodle GeniAI plugin
Version 2.3.6
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.9 / 10
AI Severity High
Vendor Moodle
Product GeniAI plugin
Version 2.3.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.