Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px56-6vfj-h8xp

Опубликовано: 21 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 7.2

Описание

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

EPSS

Процентиль: 13%
0.00044
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
nvd
15 дней назад

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

CVSS3: 7.2
debian
15 дней назад

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability ...

EPSS

Процентиль: 13%
0.00044
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79