If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2179419 | issue tracking |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/ | vendor advisory |
https://moodle.org/mod/forum/discuss.php?d=445064 | patch vendor advisory issue tracking |