PT-2018-10163 · Moodle · Moodle

Les Bell

·

Published

2018-07-10

·

Updated

2022-05-13

·

CVE-2018-10891

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.5.1 Moodle versions prior to 3.4.4 Moodle versions prior to 3.3.7 Moodle versions prior to 3.1.13
Description A flaw was found in the software. When a quiz question bank is imported, it is possible for the question preview to execute JavaScript written into the question bank.
Recommendations For versions prior to 3.5.1, update to version 3.5.1 or later. For versions prior to 3.4.4, update to version 3.4.4 or later. For versions prior to 3.3.7, update to version 3.3.7 or later. For versions prior to 3.1.13, update to version 3.1.13 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10891
GHSA-P7V9-GJRH-563X

Affected Products

Moodle