Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1870 | Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. |
Github GHSA |
GHSA-xqhh-253w-4q5f | Moodle Cross-site Scripting (XSS) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=458386 |
|
History
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Fri, 28 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-03-28T18:42:32.011Z
Reserved: 2024-04-29T13:02:30.266Z
Link: CVE-2024-33998
Updated: 2024-08-02T02:42:59.711Z
Status : Analyzed
Published: 2024-05-31T20:15:09.890
Modified: 2025-05-30T16:47:37.693
Link: CVE-2024-33998
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA