PT-2014-5387 · Moodle · Moodle

Skylar Kelty

·

Publicado

2014-07-29

·

Atualizado

2020-12-01

·

CVE-2014-3549

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 2.7.x through 2.7.0
Description A cross-site scripting issue exists due to improper handling of a crafted username during the logging of an invalid login attempt. This occurs in the get description function in lib/classes/event/user login failed.php.
Recommendations For Moodle versions 2.7.x through 2.7.0, update to version 2.7.1 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3549

Produtos afetados

Moodle