Boletines de Vulnerabilidades

MSA-22-0031: Stored XSS possible in some "social" user profile fields


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. The "social" user profile field type performed insufficient escaping on some fields, resulting in a stored XSS risk.Severity/Risk:SeriousVersions affected:4.0 to 4.0.4 and 3.11 to 3.11.10Versions fixed:4.0.5 and 3.11.11Reported by:Bernardo CabralWorkaround:Update "social" user profile fields so their visibility is set to "not visible", until the patch is applied.CVE identifier:CVE-2022-45151Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=440771&parent=1773539

Identificadores estándar

Propiedad Valor
CVE CVE-2022-45151.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2022-11-22
Ministerio de Defensa
CNI
CCN
CCN-CERT