Description
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6801 | In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects Moodle 3.11 and Moodle 3.10.4 and Moodle 3.9.7. |
Github GHSA |
GHSA-fm6m-fg23-67jq | Moodle Cross-site Scripting vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:01:57.457Z
Reserved: 2021-07-12T00:00:00.000Z
Link: CVE-2021-36568
No data.
Status : Modified
Published: 2022-09-13T22:15:08.793
Modified: 2024-11-21T06:13:50.130
Link: CVE-2021-36568
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA