CVE-2025-60507

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.
Configurations

No configuration.

History

21 Oct 2025, 19:31

Type Values Removed Values Added
CWE CWE-79

21 Oct 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 18:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-60507

Mitre link : CVE-2025-60507

CVE.ORG link : CVE-2025-60507


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')