CVE-2014-3551 Multiple XSS漏洞

From PwnWiki
Revision as of 11:26, 7 April 2021 by Pwnwiki (talk | contribs) (Created page with "==INFO== Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x be...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

INFO

Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.


XSS

../mod/assign/view.php?id={id}&rownum=0