Boletines de Vulnerabilidades

MSA-21-0015: Stored XSS in quiz grading report via user ID number


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.Severity/Risk:MinorVersions affected:3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versionsVersions fixed:3.11, 3.10.4, 3.9.7, 3.8.9 and 3.5.18Reported by:Paul HoldenCVE identifier:CVE-2021-32475Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71130Tracker issue:MDL-71130 Stored

More info:

https://moodle.org/mod/forum/discuss.php?d=422309&parent=1701633

Identificadores estándar

Propiedad Valor
CVE CVE-2021-32475.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2021-05-18

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT