CVE-2026-102586

Summary

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.

Affected Software

VendorProductVersion RangeStatus
5.2.0 < 5.2.2affected
5.1.0 < 5.1.6affected
5.0.0 < 5.0.9affected
0 < 4.5.13affected

Weaknesses

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References