Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T20:53:21.915Z

Reserved: 2023-10-29T00:00:00

Link: CVE-2023-46858

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.915Z

cve-icon NVD

Status : Modified

Published: 2023-10-29T01:15:41.087

Modified: 2024-11-21T08:29:26.310

Link: CVE-2023-46858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses