PT-2023-32168 · Moodle+8 · Moodle+6

Paul Holden

·

Published

2023-11-09

·

Updated

2024-03-06

·

CVE-2023-5546

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue concerns a stored XSS risk in the quiz grading report, where ID numbers were not properly sanitized. This could potentially allow for malicious script execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2023-5546
CVE-2023-5546
GHSA-9724-H8P7-R3JV

Affected Products

Moodle
Ckeditor4
Enterprise Linux
Fedora
Moodle/Moodle
Upx
Wireshark