Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-7830
HistoryNov 24, 2014 - 12:00 a.m.

CVE-2014-7830

2014-11-2400:00:00
ubuntu.com
ubuntu.com
10

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

48.3%

Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in
the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x
before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to
inject arbitrary web script or HTML by leveraging the
mod/feedback:mapcourse capability to provide a searchcourse parameter.

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

48.3%