CVE-2014-9059 – moodle/moodle
Package
Manager: composer
Name: moodle/moodle
Vulnerable Version: >=0 <2.5.9 || >=2.6.0 <2.6.6 || >=2.7.0 <2.7.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.0032 pctl0.54462
Details
Moodle does not provide charset information in HTTP headers lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.
Metadata
Created: 2022-05-13T01:12:43Z
Modified: 2024-01-25T20:28:13Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-crcq-pw8h-9xwf/GHSA-crcq-pw8h-9xwf.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-crcq-pw8h-9xwf
Finding: F008
Auto approve: 1