CVE-2025-26529 is a stored cross-site scripting vulnerability in Moodle affecting description information displayed in the site administration live log. The issue is caused by insufficient sanitization of stored content before it is rendered in the administrative logging interface. An attacker able to influence the logged description data can cause malicious script to be persistently stored and later executed in the browser of an administrator viewing the live log.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a CTF web challenge inspired by real-world vulnerabilities (notably, log poisoning and admin session hijack in Moodle). It consists of a PHP web application with multiple user roles (admin, student, guest), a SQLite backend, and a Python-based admin bot that simulates an admin visiting user-submitted URLs. The main exploit path involves: 1. Supplying a crafted WebFinger profile URL (e.g., attacker@evil.com) via the profile search interface, which is fetched server-side and logged. 2. The log entry is displayed in the admin's log viewer (/admin/logs.php), which is vulnerable to stored XSS. 3. By injecting a malicious JavaScript payload, an attacker can hijack the admin's session when the admin bot visits the log page. 4. With the stolen session, the attacker can access the privileged /admin/flag.php endpoint to retrieve the flag. The repository contains both the challenge code and a bot implementation (using Selenium and Flask) to automate admin actions. The endpoints of interest include the log viewer, the external WebFinger fetcher (which can be abused for SSRF), and the flag endpoint. The exploit demonstrates a chain of vulnerabilities: SSRF, stored XSS, and privilege escalation via session hijacking. The codebase is well-structured, with clear separation between challenge logic, bot automation, and supporting resources.
This repository is a Proof of Concept (PoC) exploit for CVE-2025-26529, targeting Moodle 4.4.5. It demonstrates a full attack chain: SSRF to XSS, stealing the admin's session cookie, and using that cookie to achieve remote code execution (RCE) via a webshell. The repository contains: - `console.py`: An interactive Python console to communicate with a webshell on the target Moodle instance, allowing command execution and file download. - `cookie.js` and `server.py`: JavaScript and a Flask server to facilitate cookie theft via XSS. The JavaScript exfiltrates the victim's page and cookies to the attacker's server. - `steal.php`: A PHP script to log stolen cookies and related data. - `xss_redirect.php`: A PHP script that redirects the victim to a URL that loads the attacker's malicious JavaScript for cookie theft. The exploit requires the attacker to host the provided scripts, modify the placeholder IP addresses, and target a vulnerable Moodle instance. The main attack vectors are web-based (XSS, SSRF) and network-based (HTTP endpoints for exfiltration and webshell control). The endpoints are customizable and must be set to the attacker's infrastructure. The exploit is a PoC, not weaponized, but demonstrates the full chain from XSS to RCE.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.