Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29713
HistoryMar 16, 2021 - 4:34 a.m.

Cross-Site Scripting (XSS)

2021-03-1604:34:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
moodle
vulnerability
cross-site scripting
user profile
javascript
browser
arbitrary payload

EPSS

0.001

Percentile

33.0%

moodle/moodle is vulnerable to cross-site scripting (XSS). An attacker is able to inject and execute arbitrary Javascript in user’s browser via by storing a malicious payload within the ID number from the user profile field.