PT-2023-32168 · Moodle+8 · Moodle+6

·

CVE-2023-5546

·

Published

2023-11-09

·

Updated

2024-03-06

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue concerns a stored XSS risk in the quiz grading report, where ID numbers were not properly sanitized. This could potentially allow for malicious script execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2023-5546
CVE-2023-5546
GHSA-9724-H8P7-R3JV

Affected Products

Moodle
Ckeditor4
Enterprise Linux
Fedora
Moodle/Moodle
Upx
Wireshark