CVE-2024-34006

MEDIUM4.3EPSS 0.42%

moodle: unsanitized HTML in site log for config_log_created

發布日:2024/5/31修改日:2025/5/31

描述

The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

參考連結(5)