Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrcj-6fjw-3h9h

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Moodle XSS Vulnerability

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6.0, < 3.6.3

3.6.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5.0, < 3.5.5

3.5.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.2.0, < 3.4.8

3.4.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 3.1.17

3.1.17

EPSS

Процентиль: 78%
0.01255
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 6 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
nvd
около 6 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
debian
около 6 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

EPSS

Процентиль: 78%
0.01255
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79