Boletines de Vulnerabilidades

MSA-22-0031: Stored XSS possible in some "social" user profile fields

   
Software afectado PHP
 
by Michael Hawkins. The "social" user profile field type performed insufficient escaping on some fields, resulting in a stored XSS risk.Severity/Risk:SeriousVersions affected:4.0 to 4.0.4 and 3.11 to 3.11.10Versions fixed:4.0.5 and 3.11.11Reported by:Bernardo CabralWorkaround:Update "social" user profile fields so their visibility is set to "not visible", until the patch is applied.CVE identifier:CVE-2022-45151Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=440771&parent=1773539