The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
History

Tue, 05 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-22T00:00:00

Updated: 2024-11-05T14:47:25.554Z

Reserved: 2024-03-08T00:00:00

Link: CVE-2024-28593

cve-icon Vulnrichment

Updated: 2024-08-02T00:56:57.949Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-22T15:15:15.453

Modified: 2024-11-21T09:06:40.980

Link: CVE-2024-28593

cve-icon Redhat

No data.