Security Advisory

CVE-2025-60507

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-21 00:00:00
Last updated 2025-10-21 18:30:11
Assigner mitre
CVSS score 8.9
State PUBLISHED

Description

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.