CVE-2017-2578: XSS
In Moodle 3.x, there is Cross-site Scripting in the assignment submission page.
Other sources
In Moodle 3.x, there is XSS in the assignment submission page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.2.1 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2578?
CVE-2017-2578 has a medium severity rating due to its potential for cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2017-2578?
To fix CVE-2017-2578, upgrade Moodle to version 3.1.4 or later, or 3.2.1 or later.
Which versions are affected by CVE-2017-2578?
CVE-2017-2578 affects Moodle versions 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.2.0, and their corresponding beta and release candidate versions.
What type of vulnerability is CVE-2017-2578?
CVE-2017-2578 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2017-2578 be exploited remotely?
Yes, CVE-2017-2578 can be exploited remotely by users who have access to the assignment submission page.