Lucene search

K
osvGoogleOSV:GHSA-5WJH-V7C8-WRHX
HistoryMar 12, 2022 - 12:00 a.m.

Moodle stored Cross-site Scripting

2022-03-1200:00:33
Google
osv.dev
3
moodle
cross-site scripting
quiz grading
sanitizing
xss
software vulnerability

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

22.8%

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

22.8%