Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4670
HistoryJul 25, 2017 - 9:19 p.m.

Cross-site Scripting (XSS)

2017-07-2521:19:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.001

Percentile

41.9%

Moodle is vulnerable to cross-site scripting (XSS) attacks. The library does not properly filter user input in the qualification and rating fields for rubric/advanced grading. This allows a malicious user to inject and execute arbitrary script.