Moodle is vulnerable to persistent cross-site scripting (XSS) due to improper input neutralization in the calendar event subtitle field. An authenticat
more...
Moodle is vulnerable to persistent cross-site scripting (XSS) due to improper input neutralization in the calendar event subtitle field. An authenticated remote attacker could exploit this by supplying a crafted calendar event with malicious JavaScript in the subtitle track label, which could allow for the execution of arbitrary code when users view the event. Successful exploitation could allow for session hijacking and credential theft.
less...
This site uses cookies to give you the best possible experience.
By using the site, you consent to our use of cookies.
For more information, please see our
Privacy Policy