Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r2p-wpv5-683w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Moodle XSS Vulnerability

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6.0, <= 3.6.1

3.6.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5.0, <= 3.5.3

3.5.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.2.0, <= 3.4.6

3.4.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

<= 3.1.15

3.1.16

EPSS

Процентиль: 51%
0.0028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
nvd
больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVSS3: 5.4
debian
больше 6 лет назад

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

EPSS

Процентиль: 51%
0.0028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79