Описание
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | not-affected | 3.0.3+dfsg-0ubuntu1 |
cosmic | not-affected | 3.0.3+dfsg-0ubuntu1 |
devel | not-affected | 3.0.3+dfsg-0ubuntu1 |
disco | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-apps/bionic | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-apps/xenial | not-affected | 3.0.3+dfsg-0ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM modul ...
Moodle multiple cross-site scripting (XSS) vulnerabilities
Уязвимости системы управления обучением Мoodle, позволяющие нарушителю внедрить произвольный Веб- или HTML-код
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3