A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=373371 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10891 | third party advisory issue tracking |
http://www.securityfocus.com/bid/104739 | third party advisory vdb entry |