Lucene search

K
osvGoogleOSV:GHSA-X2JP-HH65-4XVF
HistoryMar 29, 2021 - 8:42 p.m.

Cross-site scripting (XSS) and Server side request forgery (SSRF) in moodle

2021-03-2920:42:15
Google
osv.dev
16
moodle
cross-site scripting
stored xss
server side request forgery
ssrf
sanitizing
software
security issue

EPSS

0.003

Percentile

69.2%

Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

EPSS

0.003

Percentile

69.2%