Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47645
HistoryJun 19, 2024 - 10:22 a.m.

Cross-site Scripting (XSS)

2024-06-1910:22:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2
moodle
software vulnerability
cross-site scripting
xss
calendar event titles
stored xss
event deletion prompt

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

moodle/moodle is vulnerable to Cross-site Scripting (XSS). The vulnerability is due to insufficient escaping of calendar event titles, leading to a stored XSS risk in the event deletion prompt.

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%