Описание
Moodle Cross-site Scripting
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
Пакеты
moodle/moodle
>= 3.1, < 3.1.12
3.1.12
moodle/moodle
>= 3.2, < 3.2.9
3.2.9
moodle/moodle
>= 3.3, < 3.3.6
3.3.6
moodle/moodle
>= 3.4, < 3.4.3
3.4.3
Связанные уязвимости
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
An issue was discovered in Moodle 3.x. An authenticated user is allowe ...