Lucene search

K
osvGoogleOSV:GHSA-P5CG-6RFR-6MX8
HistoryJun 18, 2024 - 9:30 p.m.

Moodle stored XSS via calendar's event title when deleting the event

2024-06-1821:30:36
Google
osv.dev
2
moodle
stored xss
calendar event
insufficient escaping
software security

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%