Untriaged
Permalink
CVE-2023-28331
6.1 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
Moodle: xss risk when outputting database activity filter data
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
References
-
-
FEDORA-2023-d9c13996b2 vendor-advisory
-
-
-
https://moodle.org/mod/forum/discuss.php?d=445063 x_transferred
-
-
FEDORA-2023-d9c13996b2 vendor-advisory
-
-
FEDORA-2023-d9c13996b2 vendor-advisory
-
-
-
https://moodle.org/mod/forum/discuss.php?d=445063 x_transferred
-
-
FEDORA-2023-d9c13996b2 vendor-advisory
-
-
-
https://moodle.org/mod/forum/discuss.php?d=445063 x_transferred
Affected products
moodle
- <4.1.2
- <4.0.7
- <3.11.13
- <3.9.20
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>