Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted filename.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3156 | Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted filename. |
Github GHSA |
GHSA-89f3-74m6-g27g | Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:13:33.246Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-1833
No data.
Status : Deferred
Published: 2013-03-25T21:55:04.417
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1833
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA