Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fgv-cvr8-xg48

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 1.3

Описание

Moodle vulnerable to Cross-site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 1.8.0, < 1.8.12

1.8.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 1.9.0, < 1.9.8

1.9.8

EPSS

Процентиль: 49%
0.00254
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.

redhat
около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.

nvd
около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine. NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.

debian
около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x be ...

EPSS

Процентиль: 49%
0.00254
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79