Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3810

Опубликовано: 25 мар. 2019
Источник: debian
EPSS Низкий

Описание

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodleremovedpackage

Примечания

  • https://moodle.org/mod/forum/discuss.php?d=381230#p1536767

  • http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64372

EPSS

Процентиль: 91%
0.07714
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
nvd
около 6 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 5.3
github
около 3 лет назад

Moodle XSS Vulnerability

EPSS

Процентиль: 91%
0.07714
Низкий