-
Bug
-
Resolution: Fixed
-
Minor
-
3.1.5, 3.2.2, 3.4.4, 3.5.1, 3.6
-
MOODLE_31_STABLE, MOODLE_32_STABLE, MOODLE_34_STABLE, MOODLE_35_STABLE, MOODLE_36_STABLE
-
MOODLE_34_STABLE, MOODLE_35_STABLE
-
MDL-58409-master_needs_clean_in_autocomplete_element -
Easy
-
I am reporting a XSS security issues in accordance with Bug in Tag feature.
Tag feature in any pages has XSS vulnerability.
Here are steps for how to reproduce below.
(1) Create a new quiz instance, open edit from.
(2) Enter <script> tag e.g(<script>alert("XSS!");</script>)
(3) !?
- has a non-specific relationship to
-
MDL-61359 Self-XSS when sending message to another user
-
- Closed
-
- is duplicated by
-
MDL-58923 Autocomplete form element does not escape string when adding to the list of tags for the editing user
-
- Closed
-
- Testing discovered
-
MDL-63082 Encoding problem with tags saved with special characters
-
- Closed
-