Описание
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | not-affected | 3.0.3+dfsg-0ubuntu1 |
cosmic | not-affected | 3.0.3+dfsg-0ubuntu1 |
devel | not-affected | 3.0.3+dfsg-0ubuntu1 |
disco | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-apps/bionic | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-apps/xenial | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
Показывать по
EPSS
3.5 Low
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML into an external application via a crafted string that is visible to web services.
Cross-site scripting (XSS) vulnerability in the external_format_text f ...
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю внедрить произвольный веб или HTML-код
EPSS
3.5 Low
CVSS2