{"id":"CVE-2023-23921","summary":"Moodle: reflected xss risk in some returnurl parameters","details":"The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.","aliases":["BIT-moodle-2023-23921","GHSA-97qf-pq7x-964m"],"modified":"2026-08-12T03:51:24.615940394Z","published":"2023-02-17T00:00:00Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/23xxx/CVE-2023-23921.json","unresolved_ranges":[{"extracted_events":[{"introduced":"4.1.0"},{"fixed":"4.1.1"},{"introduced":"4.0.0"},{"fixed":"4.0.6"},{"introduced":"3.11.0"},{"fixed":"3.11.12"},{"fixed":"3.9.19"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"fedora"},"references":[{"type":"WEB","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-76810"},{"type":"WEB","url":"https://git.moodle.org"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=443272#p1782021"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/23xxx/CVE-2023-23921.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23921"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2162526"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moodle/moodle","events":[{"introduced":"500c131eb49771e36f68d151dfa37fef5a9bc2df"},{"fixed":"fc01a52823ce31d57c2964daf3ead094869dd016"},{"introduced":"94f2d3fc4b974c5c7d500988c56b7ca15f58d7ec"},{"fixed":"f21e1443dc0cd26891becf3aa5bea735211dd8a8"},{"introduced":"8b359ad7a63cf219110bca80552fe3d4ea2a635d"},{"fixed":"b864c78a31e0b2c245e2cf4ff6a566be435fec3a"},{"introduced":"0ea3d45e04c3d54a3a472ddcb11606b30e227c50"},{"last_affected":"0ea3d45e04c3d54a3a472ddcb11606b30e227c50"}],"database_specific":{"extracted_events":[{"introduced":"3.9.0"},{"fixed":"3.9.19"},{"introduced":"3.11.0"},{"fixed":"3.11.12"},{"introduced":"4.0.0"},{"fixed":"4.0.6"},{"introduced":"4.1.0-NA"},{"last_affected":"4.1.0-NA"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*"]}}],"versions":["4.1.0-NA","v4.1.0","v3.9.18","v3.11.11","v4.0.5","v3.11.10","v3.9.17","v4.0.4","v3.9.16","v3.11.9","v4.0.3","v4.0.2","v3.11.8","v3.9.15","v3.9.14","v4.0.1","v3.11.7","v4.0.0","v3.11.6","v3.9.13","v3.11.5","v3.9.12","v3.11.4","v3.9.11","v3.11.3","v3.9.10","v3.11.1","v3.11.2","v3.9.9","v3.9.8","v3.11.0","v3.9.7","v3.9.6","v3.9.5","v3.9.4","v3.9.3","v3.9.2","v3.9.1","v3.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23921.json"}}],"schema_version":"1.9.0"}