CVE-2017-2645: Moodle

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

Affected products

  • Moodle Moodle: version 3.1.0 only; version 3.1.1 only; version 3.1.2 only; version 3.1.3 only; version 3.1.4 only; version 3.2.0 only; …

Published 2017-03-26. Last modified 2026-06-17.