Описание
Moodle XSS Vulnerability
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-10891
- https://github.com/moodle/moodle/commit/0b18d0c960c27994dd9870d286f2da3fa5868c06
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10891
- https://moodle.org/mod/forum/discuss.php?d=373371
- https://web.archive.org/web/20210124185945/https://www.securityfocus.com/bid/104739
Пакеты
moodle/moodle
>= 3.5.0, < 3.5.1
3.5.1
moodle/moodle
>= 3.4.0, < 3.4.4
3.4.4
moodle/moodle
>= 3.3.0, < 3.3.7
3.3.7
moodle/moodle
>= 3.2.0, < 3.2.10
3.2.10
moodle/moodle
>= 3.1.0, < 3.1.13
3.1.13
Связанные уязвимости
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13 ...