Moodle

xss when adding a new course

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Minor Minor
  • Resolution: Not a bug
  • Affects Version/s: 1.8
  • Fix Version/s: None
  • Component/s: Administration
  • Labels:
    None
  • Environment:
    mamp
  • Affected Branches:
    MOODLE_18_STABLE

Description

When adding a new course it is possible to inject XSS. This will be triggered visiting the site index.

Activity

Hide
Petr Škoda (skodak) added a comment -

This is a feature - teacher submitted data is not filtered, they would not be able to do much with filtering everywhere.

Show
Petr Škoda (skodak) added a comment - This is a feature - teacher submitted data is not filtered, they would not be able to do much with filtering everywhere.

People

Vote (0)
Watch (0)

Dates

  • Created:
    Updated:
    Resolved: