Описание
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
Ссылки
- Broken LinkThird Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
5.4 Medium
CVSS3
4.8 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
Связанные уязвимости
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...
EPSS
5.4 Medium
CVSS3
4.8 Medium
CVSS3
3.5 Low
CVSS2