Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m63h-q4x3-6hwj

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 2.2.10

2.2.10

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.7

2.3.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.4.0, < 2.4.4

2.4.4

EPSS

Процентиль: 69%
0.00605
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 12 лет назад

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.

nvd
около 12 лет назад

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.

debian
около 12 лет назад

The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10 ...

EPSS

Процентиль: 69%
0.00605
Низкий

Дефекты

CWE-20