CVE-2026-102586
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 30, 2026
Vendor
unknown
Description
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.