Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm4w-8vc6-2j4h

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Moodle XSS Vulnerability

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6.0, < 3.6.1

3.6.1

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5.0, < 3.5.3

3.5.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.6

3.4.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.1.0, < 3.1.15

3.1.15

EPSS

Процентиль: 91%
0.07714
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
nvd
около 6 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

CVSS3: 6.1
debian
около 6 лет назад

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to ...

EPSS

Процентиль: 91%
0.07714
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79