MSA-23-0002: Reflected XSS risk in blog search

by Michael Hawkins. Blog search required additional sanitizing to prevent a reflected XSS risk.Severity/Risk:SeriousVersions affected:4.1 and 4.0 to 4.0.5Versions fixed:4.1.1, 4.0.6Reported by:Unknown (name not provided)CVE identifier:CVE-2023-23922Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-76861Tracker issue:MDL-76861 Reflected XSS risk in blog search More info: https://moodle.org/mod/forum/discuss.php?d=443273&parent=1782022

MSA-23-0003: Possible to set the preferred "start page" of other users

by Michael Hawkins. Insufficient limitations on the "start page" preference made it possible to set that preference for another user. (Note: This was still limited to the pre-defined start page options)Severity/Risk:MinorVersions affected:4.1, 4.0 to 4.0.5, 3.11 to 3.11.11, 3.9 to 3.9.18 and earlier unsupported versionsVersions fixed:4.1.1, 4.0.6, 3.11.12 and 3.9.19Reported by:Paul HoldenCVE identifier:CVE-2023-23923Changes More info: https://moodle.org/mod/forum/discuss.php?d=443274&parent=1782023

MSA-23-0001: Reflected XSS risk in some returnurl parameters

by Michael Hawkins. Some returnurl parameters required additional sanitizing to prevent a reflected XSS risk.Severity/Risk:SeriousVersions affected:4.1, 4.0 to 4.0.5, 3.11 to 3.11.11, 3.9 to 3.9.18 and earlier unsupported versionsVersions fixed:4.1.1, 4.0.6, 3.11.12 and 3.9.19Reported by:DegrangeMCVE identifier:CVE-2023-23921Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-76810Tracker issue:MDL-76810 Reflected XSS risk in some returnurl More info: https://moodle.org/mod/forum/discuss.php?d=443272&parent=1782021
Translate »