Boletines de Vulnerabilidades

MSA-19-0026: Blind XSS reflected in some locations where user email is displayed


Información sobre el sistema

   
Software afectado PHP

Descripción

von Michael Hawkins. User emails required additional sanitizing to prevent blind XSS risk on some pages.Severity/Risk:MinorVersions affected:3.7 to 3.7.2Versions fixed:3.7.3Reported by:Yuri ZwaigCVE identifier:CVE-2019-14881Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-66762Tracker issue:MDL-66762 Blind XSS reflected in some locations where user email is displayed

More info:

https://moodle.org/mod/forum/discuss.php?d=393584&parent=1586746

Identificadores estándar

Propiedad Valor
CVE CVE-2019-14881.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2020-03-31

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT