Improper Neutralization of Special Elements in Output Used by a Downstream Component in Moodle - CVE-2018-10891

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Moodle - CVE-2018-10891

Published: July 10, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31274
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10891
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2018-10891

Install update from vendor's website.

Moodle - update to 3.5.1
moodle - addressed in versions 3.1.13-1.el7, 3.1.13-2.el7, 3.3.7-1.fc27, 3.4.4-1.fc28

External References

Related Security Bulletins