Boletines de Vulnerabilidades

MSA-23-0007: Algebra filter XSS when filter is misconfigured


Información sobre el sistema

   
Software afectado PHP

Descripción

von Michael Hawkins. If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.Severity/Risk:MinorVersions affected:4.1 to 4.1.1, 4.0 to 4.0.6, 3.11 to 3.11.12, 3.9 to 3.9.19 and earlier unsupported versionsVersions fixed:4.1.2, 4.0.7, 3.11.13 and 3.9.20Reported by:Petr SkodaWorkaround:Ensure that if the algebra filter is enabled, it is correctly configured and functional (otherwise, ensure it is disabled).CVE

More info:

https://moodle.org/mod/forum/discuss.php?d=445064&parent=1788897

Identificadores estándar

Propiedad Valor
CVE CVE-2023-28332.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2023-04-26
Ministerio de Defensa
CNI
CCN
CCN-CERT