Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

GHSA-28gc-4qq5-8q26: Moodle Cross-site Scripting vulnerability

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

ghsa
#xss#vulnerability#git
GHSA-9724-h8p7-r3jv: Moodle Cross-site Scripting vulnerability

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-5541: Official Moodle git projects - moodle.git/search

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVE-2023-5547: Official Moodle git projects - moodle.git/search

The course upload preview contained an XSS risk for users uploading unsafe data.

CVE-2023-5544: Official Moodle git projects - moodle.git/search

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

CVE-2023-5546: Official Moodle git projects - moodle.git/search

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-45885: XSS in NASAs Open MCT v3.1.0

Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

CVE-2023-36688: WordPress Simple Site Verify plugin <= 1.0.7 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.

CVE-2023-47488: bugplorer

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVE-2023-46492: gist:a75b618419d5afb137cd5a29e8156420

Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.