Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwv7-h477-wrv7

Опубликовано: 26 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Moodle Stored XSS and blind SSRF possible via SCORM track details

A stored Cross-site Scripting (XSS) and blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9, < 3.9.15

3.9.15

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11, < 3.11.8

3.11.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.0, < 4.0.2

4.0.2

EPSS

Процентиль: 31%
0.00116
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-918

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
nvd
почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
debian
почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs ...

CVSS3: 7.2
fstec
почти 3 года назад

Уязвимость виртуальной обучающей среды moodle, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код и раскрыть защищаемую информацию

CVSS3: 9.8
redos
больше 2 лет назад

Множественные уязвимости Moodle

EPSS

Процентиль: 31%
0.00116
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-918