Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq3r-xmqf-p5w7

Опубликовано: 29 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

EPSS

Процентиль: 30%
0.00109
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 1 года назад

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
nvd
больше 1 года назад

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
debian
больше 1 года назад

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflecte ...

EPSS

Процентиль: 30%
0.00109
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79