A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
2018-07-10T18:29:00.313
2024-11-21T03:42:14.247
Modified
CVSSv3.1: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 3.1.13 | Yes |
Application | moodle | moodle | < 3.3.7 | Yes |
Application | moodle | moodle | < 3.4.4 | Yes |
Application | moodle | moodle | < 3.5.1 | Yes |