CVE-2025-60507

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.
Configurations

No configuration.

History

No history.

Information

Published : 2025-10-21 18:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-60507

Mitre link : CVE-2025-60507

CVE.ORG link : CVE-2025-60507


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')