Lucene search

K
cvelistMitreCVELIST:CVE-2014-9059
HistoryNov 24, 2014 - 11:00 a.m.

CVE-2014-9059

2014-11-2411:00:00
mitre
www.cve.org
3

AI Score

5.6

Confidence

High

EPSS

0.003

Percentile

71.9%

lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

AI Score

5.6

Confidence

High

EPSS

0.003

Percentile

71.9%

Related for CVELIST:CVE-2014-9059