|
|
Log in / Subscribe / Register

moodle: cross-site scripting

Package(s):moodle CVE #(s):CVE-2015-0216
Created:February 16, 2015 Updated:February 18, 2015
Description: From the Red Hat bugzilla:

MSA-15-0006: Capability to grade Lesson module is missing XSS bitmask

Description: Users with capability to grade in Lesson module were not reported as users with XSS risk but their feedback was displayed without cleaning

Issue summary: mod/lesson:grade capability missing RISK_XSS but essay feedback is displayed with noclean=true

Severity/Risk: Minor
Versions affected: 2.8 to 2.8.1
Versions fixed: 2.8.2
Reported by: Damyon Wiese
Issue no.: MDL-48034

Alerts:
Fedora FEDORA-2015-1751 moodle 2015-02-15

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds