Lucene search

K
osvGoogleOSV:GHSA-MX5G-3VXH-RGM8
HistoryMay 13, 2022 - 1:13 a.m.

Moodle vulnerable to XSS via bundled spikephpcoverage library

2022-05-1301:13:17
Google
osv.dev
8
moodle
xss
vulnerability
spikephpcoverage
library
remote attackers
web script
html
unspecified vectors
software

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

55.4%

Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

55.4%