Количество 5
Количество 5

CVE-2015-3174
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.

CVE-2015-3174
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading.
CVE-2015-3174
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ...
GHSA-6r7x-6q98-qcqp
Moodle does not set the RISK_XSS bit for graders

BDU:2015-10887
Уязвимость системы управления обучением Мoodle, позволяющая нарушителю проводить межсайтовый скриптинг
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2015-3174 mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading. | CVSS2: 3.5 | 0% Низкий | около 10 лет назад |
![]() | CVE-2015-3174 mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted gradebook feedback during manual quiz grading. | CVSS2: 3.5 | 0% Низкий | около 10 лет назад |
CVE-2015-3174 mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2 ... | CVSS2: 3.5 | 0% Низкий | около 10 лет назад | |
GHSA-6r7x-6q98-qcqp Moodle does not set the RISK_XSS bit for graders | 0% Низкий | около 3 лет назад | ||
![]() | BDU:2015-10887 Уязвимость системы управления обучением Мoodle, позволяющая нарушителю проводить межсайтовый скриптинг | CVSS2: 3.5 | 0% Низкий | около 10 лет назад |
Уязвимостей на страницу