CVE Vulnerabilities

CVE-2018-10891

Published: Jul 10, 2018 | Modified: Oct 23, 2020
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 3.1 (including) 3.1.13 (excluding)
Moodle Moodle 3.3 (including) 3.3.7 (excluding)
Moodle Moodle 3.4 (including) 3.4.4 (excluding)
Moodle Moodle 3.5 (including) 3.5.1 (excluding)

References