Boletines de Vulnerabilidades

MSA-23-0048: Stored XSS in grader report via user ID number


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. ID numbers displayed in the grader report required additional sanitizing to prevent a stored XSS risk.Severity/Risk:MinorVersions affected:4.3 and 4.2 to 4.2.3Versions fixed:4.3.1 and 4.2.4Reported by:Paul HoldenCVE identifier:CVE-2023-6665Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80239Tracker issue:MDL-80239 Stored XSS in grader report via user ID number

More info:

https://moodle.org/mod/forum/discuss.php?d=453762&parent=1823289

Identificadores estándar

Propiedad Valor
CVE CVE-2023-6665.

Histórico de versiones

Versión Comentario Data
Ministerio de Defensa
CNI
CCN
CCN-CERT