-
Improvement
-
Resolution: Fixed
-
Minor
-
None
-
3.1, 3.3
-
MOODLE_31_STABLE, MOODLE_33_STABLE
-
Easy
Authentication plugins do not properly sanitise the inputs for fields. So you are able to insert scripts etc. Only users with the capability moodle/site:config which has XSS risk anyway can access it so it is only really a usability concern, as it may confused admins in some cases
Originally reported by S3curityB3ast at MDL-53109 MDL-53134
- will be (partly) resolved by
-
MDL-12689 convert all auth plugins to use settings.php
-
- Closed
-