Lucene search

K
osvGoogleOSV:GHSA-CH68-5R37-P7C3
HistoryMay 13, 2022 - 1:12 a.m.

Moodle cross-site scripting (XSS) vulnerability

2022-05-1301:12:52
Google
osv.dev
8
moodle
cross-site scripting
vulnerability
url downloader
repository
remote attackers
arbitrary web script
html

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.3%

Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.3%