Lucene search

K
osvGoogleOSV:GHSA-M8F5-9WG8-2C3H
HistoryMay 13, 2022 - 1:12 a.m.

Moodle multiple cross-site scripting (XSS) vulnerabilities

2022-05-1301:12:41
Google
osv.dev
5
moodle
xss
vulnerabilities
advanced-grading
remote authenticated users
web script
html
rubric

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

41.9%

Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

References

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

41.9%