Vulnerability Bulletins

MSA-17-0004: XSS in assignment submission page

   
Affected software PHP
 
by Marina Glancy. Description:HTML injection with potential XSS attack was possible by modifying URL for assignment submission and tricking another user into following itIssue summary:XSS in assignment submission pageSeverity/Risk:MinorVersions affected:3.2 and 3.1 to 3.1.3Versions fixed:3.2.1 and 3.1.4 (also backported to 2.7.18 and 3.0.8 as a precaution)Reported by:Ago Luberg and Wael AbuSeadaIssue no.:MDL-57580CVE identifier:CVE-2017-2578Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=345915&parent=1395034