CVE-2024-38274
PHP vulnerability analysis and mitigation

Overview

CVE-2024-38274 is a security vulnerability discovered in Moodle's calendar functionality. The vulnerability was disclosed on June 18, 2024, and affects Moodle versions 4.4, 4.3 to 4.3.4, 4.2 to 4.2.7, 4.1 to 4.1.10, and earlier unsupported versions. The issue stems from insufficient escaping of calendar event titles, which results in a stored Cross-Site Scripting (XSS) risk specifically in the event deletion prompt (Moodle Forum).

Technical details

The vulnerability is classified as a stored Cross-Site Scripting (XSS) issue (CWE-79) that occurs due to improper neutralization of input during web page generation. According to CISA's assessment, the vulnerability has been assigned a CVSS v3.1 Base Score of 6.1 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating that it is network-accessible, requires low attack complexity, needs no privileges, but does require user interaction (NVD).

Impact

The vulnerability could allow an attacker to execute stored XSS attacks through calendar event titles, potentially leading to the compromise of user data and session information when users attempt to delete calendar events. The impact is considered moderate as it requires user interaction and only affects specific functionality within the calendar system (CERT-FR).

Exploitability

The vulnerability requires an attacker to create a specially crafted calendar event title that would be triggered when users attempt to delete the event. The exploit can be executed remotely and requires no special privileges, though it does need user interaction to be successful (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Moodle versions 4.4.1, 4.3.5, 4.2.8, and 4.1.11. Organizations running affected versions should upgrade to these patched versions. The fix has been implemented through proper escaping of calendar event titles in the deletion prompt (Moodle Forum).

Community reactions

The vulnerability was reported by security researcher Meirza and has been acknowledged by the Moodle security team. Fedora Project has released security updates for both Fedora 39 and 40 to address this vulnerability along with other security issues (Fedora Update).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56825HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-49992MEDIUM6.3
  • PHP logoPHP
  • kimai/kimai
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management