web analytics

MSA-22-0031: Stored XSS possible in some "social" user profile fields

Rate this post

by Michael Hawkins. The “social” user profile field type performed insufficient escaping on some fields, resulting in a stored XSS risk.Severity/Risk:SeriousVersions affected:4.0 to 4.0.4 and 3.11 to 3.11.10Versions fixed:4.0.5 and 3.11.11Reported by:Bernardo CabralWorkaround:Update “social” user profile fields so their visibility is set to “not visible”, until the patch is applied.CVE identifier:CVE-2022-45151Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=440771&parent=1773539Leer másÚltimas Vulnerabilidades

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post

More Latest Published Posts