Описание
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | ignored | end of standard support, was needs-triage |
cosmic | ignored | end of life |
devel | DNE | |
disco | ignored | end of life |
eoan | ignored | end of life |
esm-apps/bionic | needs-triage | |
esm-apps/xenial | needs-triage | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needs-triage] |
esm-infra/focal | DNE |
Показывать по
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move such a block to other pages where they can be viewed by other users.
An issue was discovered in Moodle 3.x. An authenticated user is allowe ...
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3