Описание
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | 2.7.11+dfsg-2 |
bionic | not-affected | 2.7.11+dfsg-2 |
cosmic | not-affected | 2.7.11+dfsg-2 |
devel | not-affected | 2.7.11+dfsg-2 |
disco | not-affected | 2.7.11+dfsg-2 |
esm-apps/bionic | not-affected | 2.7.11+dfsg-2 |
esm-apps/xenial | not-affected | 2.7.11+dfsg-2 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
Показывать по
EPSS
3.5 Low
CVSS2
5.4 Medium
CVSS3
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering a crafted survey answer.
Multiple cross-site scripting (XSS) vulnerabilities in the survey modu ...
Moodle multiple cross-site scripting (XSS) vulnerabilities
Уязвимости системы управления обучением Мoodle, позволяющие нарушителю внедрить произвольный Веб- или HTML-код
EPSS
3.5 Low
CVSS2
5.4 Medium
CVSS3