Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47700
HistoryJun 24, 2024 - 4:47 a.m.

Cross-site Scripting (XSS)

2024-06-2404:47:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
moodle
cross-site scripting
xss
user input
field name parameter
new activity
improper validation
vulnerability
software
attacker
xss attacks

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

5.8

Confidence

High

moodle/moodle is vulnerable to Cross-site Scripting (XSS). The vulnerability is caused due to improper validation of user input in the “Field Name” parameter associated with a new activity, which allows an attacker to perform XSS attacks.

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

5.8

Confidence

High