CVE-2024-28593
Cross-site Scripting in Moodle Chat
5.4
MEDIUM
CVSS 3.1
EPSS 0.55%
描述
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
如何修補 CVE-2024-28593
要修補 CVE-2024-28593,請將受影響套件升級到下列已修補版本。
- —升級至 4.3.4 或更新版本
- —未列出修補版本
CVE-2024-28593 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 4.3.3, < 4.3.4
- from 0, <= 4.3.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |