PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-2578 Moodle CVE debrief

CVE-2017-2578 is a cross-site scripting (XSS) issue in Moodle 3.x affecting the assignment submission page. NVD rates it as medium severity, with a network-reachable attack path that requires user interaction and can impact both confidentiality and integrity in the victim’s browser context.

Vendor
Moodle
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-20
Original CVE updated
2026-05-13
Advisory published
2017-01-20
Advisory updated
2026-05-13

Who should care

Moodle administrators, school and university IT teams, and anyone running Moodle instances where students or external users submit assignments should care most. Security teams should also review any deployments that expose assignment workflows to untrusted users.

Technical summary

The NVD record classifies this issue as CWE-79 and gives it the vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. That means a remote attacker can leverage a crafted web input or content path associated with the assignment submission page so that script executes in another user’s browser after the user interacts with the page. NVD’s vulnerable CPE entries cover Moodle 3.1.0 through 3.1.3 and Moodle 3.2.0 release candidates and builds listed in the record.

Defensive priority

Medium

Recommended defensive actions

  • Review whether your Moodle deployment matches the affected 3.x versions listed in NVD and prioritize remediation for internet-facing instances.
  • Apply the vendor guidance referenced by NVD for the Moodle advisory and verify that the assignment submission page is no longer accepting unsanitized input.
  • Test the assignment submission workflow after patching to confirm no legitimate functionality regressed.
  • If immediate patching is not possible, reduce exposure by limiting who can submit assignments and monitoring for abnormal browser-side behavior on assignment pages.
  • Use standard web application protections such as output encoding and input validation controls in custom integrations or plugins around assignment handling.

Evidence notes

The CVE description states there is XSS in the Moodle 3.x assignment submission page. NVD classifies the weakness as CWE-79 and provides the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The NVD record also lists vulnerable Moodle CPEs including 3.1.0, 3.1.1, 3.1.2, 3.1.3, and 3.2.0 variants. NVD references a Moodle vendor advisory and a third-party advisory entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-2578 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-2578

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-2578 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-2578

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.