Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affecting moodle/moodle package, versions <3.5.16 >=3.8, <3.8.7 >=3.9, <3.9.4 >=3.10, <3.10.1


0.0
medium

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
    Scope Changed

    Threat Intelligence

    EPSS 0.05% (22nd percentile)
Expand this section
NVD
5.4 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-MOODLEMOODLE-6673189
  • published 24 Apr 2024
  • disclosed 24 May 2022
  • credit Ata Hakcil

How to fix?

Upgrade moodle/moodle to version 3.5.16, 3.8.7, 3.9.4, 3.10.1 or higher.

Overview

moodle/moodle is a learning platform.

Affected versions of this package are vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') due to insufficient sanitizing of TeX content when the TeX notation filter is enabled. An attacker can inject malicious scripts by crafting specific TeX content.

Note:

This is only exploitable if the TeX notation filter is enabled.