Boletines de Vulnerabilidades

MSA-19-0029: Reflected XSS possible from some fatal error messages


Información sobre el sistema

   
Software afectado PHP

Descripción

von Michael Hawkins. Fatal error messages required extra sanitizing to prevent reflected XSS risks on some pages.Severity/Risk:SeriousVersions affected:3.7 to 3.7.2, 3.6 to 3.6.6, 3.5 to 3.5.8 and earlier unsupported versionsVersions fixed:3.7.3, 3.6.7 and 3.5.9Reported by:Yuriy DyachenkoCVE identifier:CVE-2019-14884Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-66161Tracker issue:MDL-66161 Reflected XSS possible from some fatal error

More info:

https://moodle.org/mod/forum/discuss.php?d=393587&parent=1586751

Identificadores estándar

Propiedad Valor
CVE CVE-2019-14884.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2020-03-31

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT