Back to search
CVE-2014-7830
Published: Nov 24, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-47865
x_refsource_CONFIRM
1031215
vdb-entry
x_refsource_SECTRACK
71119
vdb-entry
x_refsource_BID
[oss-security] 20141117 Moodle security issues are now public
mailing-list
x_refsource_MLIST
https://moodle.org/mod/forum/discuss.php?d=275147
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now