CVE-2023-46858

CVE-2023-46858

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses … admins and teachers can post XSS-capable content, but students can not."

Source: CVE-2023-46858

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다