CVE-2024-29374 Overview
CVE-2024-29374 is a reflected Cross-Site Scripting (XSS) vulnerability in Moodle 3.10.9. The flaw exists in how the application handles user-supplied input passed to the lang URL parameter in HTTP GET requests. An attacker can craft a malicious URL that injects arbitrary JavaScript into the response rendered by the victim's browser. Successful exploitation requires user interaction, typically achieved through phishing or malicious link distribution. The vulnerability is categorized under CWE-79, Improper Neutralization of Input During Web Page Generation.
Critical Impact
Attackers can execute arbitrary JavaScript in the victim's session context, enabling session hijacking, credential theft, and unauthorized actions against the Moodle learning management system.
Affected Products
- Moodle 3.10.9
- CPE: cpe:2.3:a:moodle:moodle:3.10.9:*:*:*:*:*:*:*
- Component: moodle:moodle
Discovery Timeline
- 2024-03-21 - CVE-2024-29374 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in the NVD database
Technical Details for CVE-2024-29374
Vulnerability Analysis
The vulnerability is a reflected XSS flaw triggered through the lang query string parameter. Moodle 3.10.9 fails to properly sanitize or encode user-supplied input before including it in the rendered HTML response. When an attacker crafts a URL such as https://<moodle-host>/?lang=<payload>, the injected payload is reflected into the page markup. The victim's browser then parses and executes the payload within the origin of the Moodle instance.
Exploitation depends on tricking an authenticated or unauthenticated user into visiting the crafted URL. Because the payload executes in the context of the Moodle domain, it can read session cookies, initiate authenticated requests, and manipulate DOM content shown to the user. A public proof-of-concept is available on GitHub Gist.
Root Cause
The root cause is missing output encoding on the value assigned to the lang parameter. Moodle reflects this parameter directly into HTML without applying context-appropriate escaping. This defect is a textbook instance of CWE-79, where untrusted input crosses a trust boundary into an HTML rendering context.
Attack Vector
The attack vector is network-based and requires user interaction. An attacker distributes a crafted link, for example via email, chat, or a compromised website, that contains a JavaScript payload in the lang parameter. When a victim opens the link on a vulnerable Moodle 3.10.9 instance, the browser executes the reflected payload. The scope is changed because script executing inside the Moodle origin can affect resources authorized under other principals, such as the authenticated user session. Confidentiality and integrity impact are limited to what the victim's browser session can access.
No verified sanitized exploitation code is published beyond the referenced proof-of-concept. Refer to the GitHub Gist PoC Script for technical details.
Detection Methods for CVE-2024-29374
Indicators of Compromise
- HTTP GET requests to Moodle endpoints containing script tags, event handlers, or URL-encoded JavaScript in the lang parameter (for example ?lang=%3Cscript%3E).
- Web server access logs showing unusual Referer headers pointing to attacker-controlled domains preceding requests with a suspicious lang value.
- Client-side alerts, unexpected redirects, or session token exfiltration originating from a Moodle page.
Detection Strategies
- Deploy web application firewall (WAF) rules that inspect the lang query parameter for HTML tags, JavaScript keywords, and URL-encoded script fragments.
- Correlate Moodle access logs with browser telemetry to identify reflected payloads followed by outbound requests to unfamiliar hosts.
- Hunt for anomalous authenticated session activity following a click on external links containing lang= parameters.
Monitoring Recommendations
- Enable verbose HTTP request logging on the Moodle reverse proxy and forward logs to a centralized analytics platform.
- Alert on any lang parameter value containing characters outside the expected locale identifier pattern (for example [a-z]{2}(_[a-z]{2})?).
- Monitor for spikes in short-lived sessions or cookie theft indicators reported by browser security tooling.
How to Mitigate CVE-2024-29374
Immediate Actions Required
- Upgrade Moodle to a supported release that addresses reflected XSS handling on request parameters. Moodle 3.10.x is end-of-life and should be replaced with a currently supported branch.
- Restrict the accepted values of the lang parameter at the reverse proxy or WAF layer to a strict allow list of language codes.
- Notify users of active phishing risk and instruct them not to click Moodle links from untrusted sources until patches are applied.
Patch Information
No vendor advisory URL is available in the NVD entry for CVE-2024-29374. Administrators running Moodle 3.10.9 should migrate to a supported major version and apply all current security releases published by Moodle. Consult the Moodle Security Announcements page for release-specific fixes.
Workarounds
- Configure a WAF signature to block requests where the lang parameter contains <, >, ", ', or the string script in any case.
- Enforce a strict Content Security Policy (CSP) that disallows inline script execution and restricts script sources to trusted origins.
- Set the HttpOnly and Secure flags on Moodle session cookies to reduce the impact of successful script execution.
# Example NGINX rule to reject non-alphabetic lang values before they reach Moodle
location / {
if ($arg_lang ~* "[^a-z_]") {
return 400;
}
proxy_pass http://moodle_backend;
}
# Example Content Security Policy header
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self';" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
