Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f63-wvmx-66p2

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.9

Описание

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.

EPSS

Процентиль: 17%
0.00054
Низкий

8.9 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.9
nvd
4 месяца назад

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.

EPSS

Процентиль: 17%
0.00054
Низкий

8.9 High

CVSS3

Дефекты

CWE-79