CVE-2026-102586
Received Received - Intake

Cross-Site Scripting in Moodle Password Reset

Vulnerability report for CVE-2026-102586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in Moodle. It occurs because the username input on the password reset page is not properly sanitized. An attacker can trick an unauthenticated user into clicking a specially crafted password reset link, which executes arbitrary scripts in the victim's browser.

Detection Guidance

To detect this XSS vulnerability in Moodle, monitor for unusual activity on the password reset page. Check web server logs for requests containing suspicious username inputs or crafted reset links. Use tools like OWASP ZAP or Burp Suite to scan for XSS vulnerabilities in the password reset functionality.

Impact Analysis

This vulnerability could lead to the disclosure of sensitive information like session cookies, account compromise, or other malicious activities such as installing malware or redirecting users to malicious sites. It may also allow bypassing protection mechanisms and reading application data.

Compliance Impact

This XSS vulnerability could lead to unauthorized access to sensitive data, such as session cookies or user credentials, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if exploited in healthcare or EU-based systems.

Mitigation Strategies

Update Moodle to the latest version to patch this flaw. If an update is unavailable, disable the password reset page temporarily or restrict access to it. Implement input validation and output encoding for username fields on the reset page to prevent XSS attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart