6.1

CVE-2024-38274

moodle: stored XSS via calendar's event title when deleting the event

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 4.1.0 < 4.1.11
Moodle ≫ Moodle Version >= 4.2.0 < 4.2.8
Moodle ≫ Moodle Version >= 4.3.0 < 4.3.5
Moodle ≫ Moodle Version 4.4.0
Fedoraproject ≫ Fedora Version 39
Fedoraproject ≫ Fedora Version 40
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.29
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E/
Mailing List
https://moodle.org/mod/forum/discuss.php?d=459499
Vendor Advisory