Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgcp-m69h-p2gr

Опубликовано: 29 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting (XSS) in moodle

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9.0, < 3.9.3

3.9.3

EPSS

Процентиль: 63%
0.00449
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
nvd
больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
debian
больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

EPSS

Процентиль: 63%
0.00449
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79