Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4587
HistoryJul 18, 2017 - 8:03 a.m.

Cross-site Scripting (XSS)

2017-07-1808:03:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.002

Percentile

60.3%

Moodle is vulnerable to cross-site scripting (XSS) attacks. The attacks exist because lib/classes/event/user_login_failed.php does not escape the user-supplied username before returning it to the description during invalid login-attempt. This allows a malicious user to inject and execute arbitrary code through the username parameter.

EPSS

0.002

Percentile

60.3%